TYPO3 CMS - Broken Access Control in Backend API
Summary
| CVE | CVE-2026-47352 |
|---|---|
| State | PUBLISHED |
| Assigner | TYPO3 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-09 11:16:53 UTC |
| Updated | 2026-06-09 13:46:50 UTC |
| Description | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3. |
Risk And Classification
Primary CVSS: v4.0 5.3 MEDIUM from f4fb688c-4412-4426-b4b8-421ecf27b14a
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.004140000 probability, percentile 0.328200000 (date 2026-06-16)
Problem Types: CWE-862 | CWE-862 CWE-862 Missing Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | f4fb688c-4412-4426-b4b8-421ecf27b14a | Secondary | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 5.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
LowIntegrity
NoneAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TYPO3 | TYPO3 CMS | affected 10.4.57 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 11.0.0 11.5.51 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 12.0.0 12.4.46 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 13.0.0 13.4.31 semver | Not specified |
| CNA | TYPO3 | TYPO3 CMS | affected 14.0.0 14.3.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| typo3.org/security/advisory/typo3-core-sa-2026-015 | f4fb688c-4412-4426-b4b8-421ecf27b14a | typo3.org | |
| github.com/TYPO3/typo3/commit/17a3b7830d5931725db5fdab0cfc76d479884c96 | f4fb688c-4412-4426-b4b8-421ecf27b14a | github.com | |
| github.com/TYPO3/typo3/commit/bfe7c354168f467726020ed49299dd209a455719 | f4fb688c-4412-4426-b4b8-421ecf27b14a | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Phong Lan (en)
CNA: Oliver Hader (en)
There are currently no legacy QID mappings associated with this CVE.