{"id":"CVE-2026-107914","title":"Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive","summary":"Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requeste…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","cwe":["CWE-459","CWE-497"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T07:17:18.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107914","references":[{"url":"https://backdropcms.org/security/backdrop-sa-core-2026-006","label":"cve@mitre.org"},{"url":"https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749","label":"cve@mitre.org"},{"url":"https://github.com/backdrop/backdrop/commit/347c8e558254633205f431ce5c12321a7ae9248e","label":"cve@mitre.org"}],"tags":["nvd"],"ingestedAt":"2026-10-09T06:27:05.591Z","slug":"CVE-2026-107914","body":"## Overview\n\nBackdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the \"Synchronize, import, and export configuration\" permission. NOTE: CVE-2026-107914 refers to the vulnerability in which config.admin.inc does not ensure that a file_unmanaged_delete operation occurs. Therefore, many archives could persist: config.tar.gz, config_0.tar.gz, config_1.tar.gz, etc. There is a separate config.module issue that could allow remote access by an anonymous user, but only for the one filename config.tar.gz.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}