๐Ÿ” CVE Alert

CVE-2026-47352

UNKNOWN 0.0

TYPO3 CMS - Broken Access Control in Backend API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.

CWE CWE-862
Vendor typo3
Product typo3 cms
Published Jun 9, 2026
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 typo3 cms

Be the first to know when new unknown vulnerabilities affecting typo3 typo3 cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / TYPO3 CMS
0 < 10.4.57 11.0.0 < 11.5.51 12.0.0 < 12.4.46 13.0.0 < 13.4.31 14.0.0 < 14.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-core-sa-2026-015 github.com: https://github.com/TYPO3/typo3/commit/bfe7c354168f467726020ed49299dd209a455719 github.com: https://github.com/TYPO3/typo3/commit/17a3b7830d5931725db5fdab0cfc76d479884c96

Credits

๐Ÿ” Phong Lan Oliver Hader