Description
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
https://typo3.org/security/advisory/typo3-core-sa-2026-008
Patch patch
Git commit of main branch
https://github.com/TYPO3/typo3/commit/2030617e6f273cee7b756c695f0a48a45a31eb47
Patch patch
Git commit of 13.4 branch
https://github.com/TYPO3/typo3/commit/eb2b2251d90339d3ab55df3d4c0378ae0c780b45
Scores
CVSS v4
7.6
EPSS
0.0003
EPSS Percentile
9.1%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-178
CWE-862
Status
published
Products (15)
typo3/cms-core
0 - 10.4.57Packagist
typo3/cms-core
11.0.0 - 11.5.51Packagist
typo3/cms-core
12.0.0 - 12.4.46Packagist
typo3/cms-core
13.0.0 - 13.4.31Packagist
typo3/cms-core
14.0.0 - 14.3.3Packagist
typo3/cms-form
0 - 10.4.57Packagist
typo3/cms-form
11.0.0 - 11.5.51Packagist
typo3/cms-form
12.0.0 - 12.4.46Packagist
typo3/cms-form
13.0.0 - 13.4.31Packagist
typo3/cms-form
14.0.0 - 14.3.3Packagist
... and 5 more
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026