CVE-2026-49742High▾ TwilightTYPO3 CMS has Broken Access Control in its Media Module
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files.
Update to TYPO3 versions 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
TYPO3 CMS thanks Hyunseo Shin for reporting this issue, and to TYPO3 security team member Torben Hansen for fixing it.
typo3/cms-core >= 11.0.0, < 11.5.51typo3/cms-core >= 12.0.0, < 12.4.46typo3/cms-core >= 13.0.0, < 13.4.31typo3/cms-core >= 14.0.0, < 14.3.3typo3/cms-filelist >= 11.0.0, < 11.5.51typo3/cms-filelist >= 12.0.0, < 12.4.46typo3/cms-filelist >= 13.0.0, < 13.4.31typo3/cms-filelist >= 14.0.0, < 14.3.3Upgrade to a patched release:
typo3/cms-core 11.5.51typo3/cms-core 12.4.46typo3/cms-core 13.4.31typo3/cms-core 14.3.3typo3/cms-filelist 11.5.51typo3/cms-filelist 12.4.46typo3/cms-filelist 13.4.31typo3/cms-filelist 14.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47351MediumTYPO3 CMS: Broken Access Control in Media Module
CVE-2026-49738LowTYPO3 CMS has Broken Access Control in its File Abstraction Layer
CVE-2026-47348MediumTYPO3 CMS has Cross-Site Scripting in Indexed Search
CVE-2026-47352MediumTYPO3 CMS has Broken Access Control in Backend API
CVE-2026-49740MediumTYPO3 CMS has Insecure Deserialization via Core API
CVE-2026-47346HighTYPO3 CMS has Broken Access Control in its Form Framework