Threat Advisory

TYPO3 CMS Broken Access Control in Backend and Install Tool

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting typo3/cms-backend versions >= 13.0.0, < 13.4.34 affecting typo3/cms-core versions >= 14.0.0, < 14.3.6. The overall risk is high, as attackers can exploit cross-site scripting vulnerabilities on frontend pages to invoke backend routes and install tool endpoints with the privileges of an authenticated user session.

CVE-2026-19418 (CVSS 7.3 — Severity): A broken access control vulnerability in TYPO3 CMS allows attackers able to execute JavaScript on one of the instance's own domains to invoke backend routes and install tool endpoints via Fetch/XHR with the privileges of an authenticated victim's user session.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting typo3/cms-backend versions >= 13.0.0, < 13.4.34 affecting typo3/cms-core versions >= 14.0.0, < 14.3.6. The overall risk is high, as attackers can exploit cross-site scripting vulnerabilities on frontend pages to invoke backend routes and install tool endpoints with the privileges of an authenticated user session.

CVE-2026-19418 (CVSS 7.3 — Severity): A broken access control vulnerability in TYPO3 CMS allows attackers able to execute JavaScript on one of the instance's own domains to invoke backend routes and install tool endpoints via Fetch/XHR with the privileges of an authenticated victim's user session.[emaillocker id="1283"]

CVE-2020-11069: The referrer enforcement introduced in TYPO3-CORE-SA-2020-006 became ineffective in TYPO3 v13.0, allowing requests originating from any script running on one of the instance's own domains to be accepted by backend routes and install tool endpoints.

These vulnerabilities collectively present a high risk for administrators, who should review exposure and apply updates to affected versions.

RECOMMENDATION:

We recommend you to update TYPO3 CMS to version 13.4.34 or 14.3.6.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu