Description
Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
https://typo3.org/security/advisory/typo3-core-sa-2026-015
Patch patch
Git commit of main branch
https://github.com/TYPO3/typo3/commit/bfe7c354168f467726020ed49299dd209a455719
Patch patch
Git commit of 13.4 branch
https://github.com/TYPO3/typo3/commit/17a3b7830d5931725db5fdab0cfc76d479884c96
Scores
CVSS v4
5.3
EPSS
0.0004
EPSS Percentile
11.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (15)
typo3/cms-backend
0 - 10.4.57Packagist
typo3/cms-backend
11.0.0 - 11.5.51Packagist
typo3/cms-backend
12.0.0 - 12.4.46Packagist
typo3/cms-backend
13.0.0 - 13.4.31Packagist
typo3/cms-backend
14.0.0 - 14.3.3Packagist
typo3/cms-core
0 - 10.4.57Packagist
typo3/cms-core
11.0.0 - 11.5.51Packagist
typo3/cms-core
12.0.0 - 12.4.46Packagist
typo3/cms-core
13.0.0 - 13.4.31Packagist
typo3/cms-core
14.0.0 - 14.3.3Packagist
... and 5 more
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026