---
id: CVE-2026-85400
title: >-
  Backend administrators without system maintainer privileges were able to
  schedule any of the configuration:read, configuration:set, and
  configuration:show commands
summary: >-
  Backend administrators without system maintainer privileges were able to
  schedule any of the configuration:read, configuration:set, and
  configuration:show commands. This allowed them to modify arbitrary system
  configuration, which is nor…
severity: high
cvss: 7.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-266
  - CWE-862
vendor: TYPO3
product: typo3/cms-lowlevel
affected:
  - typo3/cms-lowlevel >= 14.2.0 < 14.3.7
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:15:18.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85400'
references:
  - url: >-
      https://github.com/TYPO3/typo3/commit/b8abe36978c63a0625aee70df078895216e7ee27
    label: f4fb688c-4412-4426-b4b8-421ecf27b14a
  - url: >-
      https://github.com/TYPO3/typo3/commit/e15da7ba0218532240578b471152f76c13cb4154
    label: f4fb688c-4412-4426-b4b8-421ecf27b14a
  - url: 'https://news.typo3.com/security/advisory/typo3-core-sa-2026-023'
    label: f4fb688c-4412-4426-b4b8-421ecf27b14a
tags:
  - nvd
  - cve.org
epss: 0.00458
epssPercentile: 0.37057
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T12:20:29.092057Z'
cvssSource: cna
ingestedAt: '2026-09-08T15:33:26.983Z'
---

## Overview

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
