CVE-2026-49738Low▾ SunlitTYPO3 CMS has Broken Access Control in its File Abstraction Layer
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be incorrectly accepted as valid when the project root was /var/www/html. Administrator users with access to the File Abstraction Layer were able to create new file storage definitions pointing to directories outside the project root, bypassing this path check.
Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
TYPO3 CMS thanks Wolfgang Klinger for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it.
typo3/cms-core < 10.4.57typo3/cms-core >= 11.0.0, < 11.5.51typo3/cms-core >= 12.0.0, < 12.4.46typo3/cms-core >= 13.0.0, < 13.4.31typo3/cms-core >= 14.0.0, < 14.3.3Upgrade to a patched release:
typo3/cms-core 10.4.57typo3/cms-core 11.5.51typo3/cms-core 12.4.46typo3/cms-core 13.4.31typo3/cms-core 14.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49742HighTYPO3 CMS has Broken Access Control in its Media Module
CVE-2026-47348MediumTYPO3 CMS has Cross-Site Scripting in Indexed Search
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
CVE-2026-47352MediumTYPO3 CMS has Broken Access Control in Backend API
CVE-2026-49740MediumTYPO3 CMS has Insecure Deserialization via Core API
CVE-2026-47346HighTYPO3 CMS has Broken Access Control in its Form Framework