πŸ” CVE Alert

CVE-2026-47346

UNKNOWN 0.0

TYPO3 CMS - Broken Access Control in Form Framework

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

CWE CWE-178 CWE-862
Vendor typo3
Product typo3 cms
Published Jun 9, 2026
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 typo3 cms

Be the first to know when new unknown vulnerabilities affecting typo3 typo3 cms are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

TYPO3 / TYPO3 CMS
0 < 10.4.57 11.0.0 < 11.5.51 12.0.0 < 12.4.46 13.0.0 < 13.4.31 14.0.0 < 14.3.3

References

NVD β†— CVE.org β†— EPSS Data β†—
typo3.org: https://typo3.org/security/advisory/typo3-core-sa-2026-008 github.com: https://github.com/TYPO3/typo3/commit/2030617e6f273cee7b756c695f0a48a45a31eb47 github.com: https://github.com/TYPO3/typo3/commit/eb2b2251d90339d3ab55df3d4c0378ae0c780b45

Credits

πŸ” Alexander KΓΌnzl Oliver Hader Benjamin Franzke