๐Ÿ” CVE Alert

CVE-2026-11607

UNKNOWN 0.0

TYPO3 CMS - Broken Access Control in Form Framework

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.

CWE CWE-862
Vendor typo3
Product typo3 cms
Published Jun 9, 2026
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 typo3 cms

Be the first to know when new unknown vulnerabilities affecting typo3 typo3 cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / TYPO3 CMS
0 < 10.4.57 11.0.0 < 11.5.51 12.0.0 < 12.4.46 13.0.0 < 13.4.31 14.0.0 < 14.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-core-sa-2026-019 github.com: https://github.com/TYPO3/typo3/commit/50974c658f647f1aece347b5d6d5acc3c87f2dca github.com: https://github.com/TYPO3/typo3/commit/040d50d082a01f9e8bd113effd91290a9bb3b69e

Credits

๐Ÿ” Ethan Oliver Hader