Executive brief
TYPO3 CMS, a popular enterprise content management system, contains a security flaw in its form-building tool. This vulnerability allows users who already have limited access to the backend to bypass file restrictions and execute malicious database commands. An attacker could use this to take full control of the website by creating new administrator accounts.
Technical details
A missing authorization and improper file extension validation vulnerability exists in the TYPO3 Form Framework (CWE-862). Backend users with access to the framework can provide form definition files that do not use the mandatory '.form.yaml' extension. These maliciously crafted files are processed by the system, leading to the execution of arbitrary SQL statements. An attacker with low-level backend privileges can exploit this to perform unauthorized database operations, such as creating new administrative user accounts. The issue is resolved in TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, and 14.3.3 LTS.
Affected products
- TYPO3 TYPO3 CMS < 10.4.57, 11.0.0 < 11.5.51, 12.0.0 < 12.4.46, 13.0.0 < 13.4.31, 14.0.0 < 14.3.3
Timeline
- 2026-06-09: disclosed
- 2026-06-09: patched
- 2026-06-12: advisory
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-pjpj-v387-x4vq
- https://github.com/TYPO3/typo3/commit/040d50d082a01f9e8bd113effd91290a9bb3b69e
- https://github.com/TYPO3/typo3/commit/50974c658f647f1aece347b5d6d5acc3c87f2dca
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-11607.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-019