---
id: CVE-2026-104476
title: >-
  Backdrop CMS before 1.35.1 contains an information disclosure vulnerability
  that allows unauthenticated attackers to retrieve configuration export
  archives left on the server after transfer
summary: >-
  Backdrop CMS before 1.35.1 contains an information disclosure vulnerability
  that allows unauthenticated attackers to retrieve configuration export
  archives left on the server after transfer. Attackers can download compressed
  archives gen…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: backdrop
product: backdrop
affected:
  - backdrop < 1.35.1
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T00:16:35.747'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104476'
references:
  - url: 'https://backdropcms.org/security/backdrop-sa-core-2026-006'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/backdrop/backdrop'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T23:34:57.410Z'
---

## Overview

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
