CVE-2026-34581 | patrickhener goshs up to 1.0.x File Download authentication bypass (GHSA-jgfx-74g2-9r6g)
A vulnerability was found in patrickhener goshs up to 1.0.x and classified as critical. Affected is an unknown function of the component File Download Handler. The manipulation results in authentication bypass using alternate channel.
This vulnerability is reported as CVE-2026-34581. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.