Description
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
https://typo3.org/security/advisory/typo3-core-sa-2026-013
Patch patch
Git commit of main branch
https://github.com/TYPO3/typo3/commit/caa6b444d7ab1bdd1eb76a68004c8be73d98e6ae
Patch patch
Git commit of 13.4 branch
https://github.com/TYPO3/typo3/commit/ad636b6183843b57c758a1e12174a75093ac93c3
Scores
CVSS v4
7.1
EPSS
0.0004
EPSS Percentile
11.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
CWE-22
Status
published
Products (12)
typo3/cms-core
11.0.0 - 11.5.51Packagist
typo3/cms-core
12.0.0 - 12.4.46Packagist
typo3/cms-core
13.0.0 - 13.4.31Packagist
typo3/cms-core
14.0.0 - 14.3.3Packagist
typo3/cms-filelist
11.0.0 - 11.5.51Packagist
typo3/cms-filelist
12.0.0 - 12.4.46Packagist
typo3/cms-filelist
13.0.0 - 13.4.31Packagist
typo3/cms-filelist
14.0.0 - 14.3.3Packagist
TYPO3/TYPO3 CMS
11.0.0 - 11.5.51
TYPO3/TYPO3 CMS
12.0.0 - 12.4.46
... and 2 more
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026