What the vulnerability does
01Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2.
Explanation of Vulnerability in Simple Terms
02Summary
Contest Gallery versions 28.1.2.2 and earlier contain an authentication bypass vulnerability. An attacker can gain full control of the application without valid credentials, reading sensitive data, modifying content, and disrupting service. The vulnerability requires only network access and no user interaction. Immediate patching is critical.
What an attacker can do
03Attacker Capabilities
Gain unauthorized access to the entire application and read, modify, or delete any data without credentials.
Potential impact on your site
04Site Impact
Complete compromise of the application and all user data; attackers can impersonate administrators and modify or delete content.
Conditions required to exploit
05Prerequisites
Network access to the application; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 28, 2026
Record updated