{"apiVersion":"1.0","identifier":"CVE-2026-71518","description":"Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves the request to the protected file, enabling unauthorized file download without credentials.","publishedAt":"2026-08-17T21:16:48","lastModifiedAt":"2026-08-18T15:17:01","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71518","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00384,"riskScore":0.78,"affectedProduct":"Typemill","affectedVersions":"<2.26.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-71518","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-71518","en":"https://www.redsauce.net/en/cves/CVE-2026-71518","fr":"https://www.redsauce.net/fr/cves/CVE-2026-71518","pt":"https://www.redsauce.net/pt/cves/CVE-2026-71518","de":"https://www.redsauce.net/de/cves/CVE-2026-71518","sk":"https://www.redsauce.net/sk/cves/CVE-2026-71518","el":"https://www.redsauce.net/el/cves/CVE-2026-71518"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-71518"}}