A vulnerability categorized as problematic has been discovered in TestLinkOpenSourceTRMS TestLink up to 1.9.20. This impacts an unknown function of the file attachmentdownload.php of the component Attachment Download. The manipulation of the argument attachment ID results in improper control of resource identifiers.
This vulnerability is identified as CVE-2026-70561. The attack can be executed remotely. There is not any exploit available.