PT-2026-27894 · Unknown · Contest Gallery

Published

2026-03-25

·

Updated

2026-03-30

·

CVE-2026-25035

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contest Gallery versions prior to 28.1.2.3
Description A flaw exists in Contest Gallery that allows for authentication bypass. This allows for authentication abuse by utilizing an alternate path or channel.
Recommendations Update Contest Gallery to version 28.1.2.3 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2026-25035

Affected Products

Contest Gallery