CVE-2026-85400
TYPO3 CMS - Missing Authorization in lowlevel commands
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.
| CWE | CWE-862 CWE-266 |
| Vendor | typo3 |
| Product | typo3 cms |
| Published | Sep 8, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for typo3 typo3 cms
Be the first to know when new unknown vulnerabilities affecting typo3 typo3 cms are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TYPO3 / TYPO3 CMS
14.2.0 < 14.3.7
References
Credits
🔍 Tharsanan Kurukulasingam Elias Häußler