🔐 CVE Alert

CVE-2026-85400

UNKNOWN 0.0

TYPO3 CMS - Missing Authorization in lowlevel commands

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.

CWE CWE-862 CWE-266
Vendor typo3
Product typo3 cms
Published Sep 8, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 typo3 cms

Be the first to know when new unknown vulnerabilities affecting typo3 typo3 cms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TYPO3 / TYPO3 CMS
14.2.0 < 14.3.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
news.typo3.com: https://news.typo3.com/security/advisory/typo3-core-sa-2026-023 github.com: https://github.com/TYPO3/typo3/commit/b8abe36978c63a0625aee70df078895216e7ee27 github.com: https://github.com/TYPO3/typo3/commit/e15da7ba0218532240578b471152f76c13cb4154

Credits

🔍 Tharsanan Kurukulasingam Elias Häußler