Description
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
https://typo3.org/security/advisory/typo3-core-sa-2026-019
Patch patch
Git commit of main branch
https://github.com/TYPO3/typo3/commit/50974c658f647f1aece347b5d6d5acc3c87f2dca
Patch patch
Git commit of 13.4 branch
https://github.com/TYPO3/typo3/commit/040d50d082a01f9e8bd113effd91290a9bb3b69e
Scores
CVSS v4
7.6
EPSS
0.0004
EPSS Percentile
11.3%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (15)
typo3/cms-core
0 - 10.4.57Packagist
typo3/cms-core
11.0.0 - 11.5.51Packagist
typo3/cms-core
12.0.0 - 12.4.46Packagist
typo3/cms-core
13.0.0 - 13.4.31Packagist
typo3/cms-core
14.0.0 - 14.3.3Packagist
typo3/cms-form
0 - 10.4.57Packagist
typo3/cms-form
11.0.0 - 11.5.51Packagist
typo3/cms-form
12.0.0 - 12.4.46Packagist
typo3/cms-form
13.0.0 - 13.4.31Packagist
typo3/cms-form
14.0.0 - 14.3.3Packagist
... and 5 more
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026