CVE-2026-49742

HIGH

TYPO3 CMS - Broken Access Control in Media Module

Title source: cna
STIX 2.1

Description

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

Scores

CVSS v4 7.1
EPSS 0.0004
EPSS Percentile 11.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-22
Status published
Products (12)
typo3/cms-core 11.0.0 - 11.5.51Packagist
typo3/cms-core 12.0.0 - 12.4.46Packagist
typo3/cms-core 13.0.0 - 13.4.31Packagist
typo3/cms-core 14.0.0 - 14.3.3Packagist
typo3/cms-filelist 11.0.0 - 11.5.51Packagist
typo3/cms-filelist 12.0.0 - 12.4.46Packagist
typo3/cms-filelist 13.0.0 - 13.4.31Packagist
typo3/cms-filelist 14.0.0 - 14.3.3Packagist
TYPO3/TYPO3 CMS 11.0.0 - 11.5.51
TYPO3/TYPO3 CMS 12.0.0 - 12.4.46
... and 2 more
Published Jun 09, 2026
Tracked Since Jun 09, 2026