๐Ÿ” CVE Alert

CVE-2026-19418

UNKNOWN 0.0

TYPO3 CMS - Broken Access Control in Backend and Install Tool

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5.

CWE CWE-346 CWE-352
Vendor typo3
Product typo3 cms
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 typo3 cms

Be the first to know when new unknown vulnerabilities affecting typo3 typo3 cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / TYPO3 CMS
13.0.0 < 13.4.34 14.0.0 < 14.3.6
TYPO3 / TYPO3 CMS
13.0.0 < 13.4.34 14.0.0 < 14.3.6
TYPO3 / TYPO3 CMS
14.0.0 < 14.3.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-core-sa-2026-021 typo3.org: https://typo3.org/security/advisory/typo3-core-sa-2020-006 github.com: https://github.com/TYPO3/typo3/commit/ae0abd329d52285fe6e92804c3608820ad45e872 github.com: https://github.com/TYPO3/typo3/commit/a0e8ee06a40e959b9e7b06a4b1cb19d3a0d3dcf7 github.com: https://github.com/TYPO3/typo3/commit/4a75e862c589c85d795d7c65dcdc835f8f413efc

Credits

๐Ÿ” Hแป• Cao Tแปซ Benjamin Franzke