CVE-2026-47351

MEDIUM

TYPO3 CMS - Broken Access Control in Clipboard

Title source: cna
STIX 2.1

Description

Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2.

Scores

CVSS v4 5.3
EPSS 0.0004
EPSS Percentile 11.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-862
Status published
Products (12)
typo3/cms-backend 0 - 10.4.57Packagist
typo3/cms-backend 11.0.0 - 11.5.51Packagist
typo3/cms-backend 12.0.0 - 12.4.46Packagist
typo3/cms-backend 13.0.0 - 13.4.31Packagist
typo3/cms-backend 14.0.0 - 14.3.3Packagist
typo3/cms-core 0 - 10.4.57Packagist
typo3/cms-core 11.0.0 - 11.5.51Packagist
typo3/cms-core 12.0.0 - 12.4.46Packagist
typo3/cms-core 13.0.0 - 13.4.31Packagist
typo3/cms-core 14.0.0 - 14.3.3Packagist
... and 2 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026