Junglewise Threat Intelligence

CVE-2026-47343: TYPO3 CMS broken access control in File Abstraction Layer

CVE-2026-47343 · Severity: high · CVSS 4 · Published 2026-06-09

Technologies: Typo3 Cms-Core. Vendors: Typo3.

Executive brief

TYPO3 CMS is a popular enterprise content management system. A vulnerability was found where low-privileged users with access to specific file folders could move, rename, or delete the root folders of those file mounts. This could lead to data loss or disruption of website operations by allowing unauthorized users to manipulate the core structure of the file system they are assigned to manage.

Technical details

A missing authorization check (CWE-862) in TYPO3 CMS allows authenticated backend users with file mount permissions to perform destructive actions on the root directory of their assigned mounts. While these users are intended to manage files within the mount, they should not have the authority to rename, move, or delete the mount point itself. An attacker with low-level backend privileges can exploit this over the network to disrupt file availability or integrity. The issue is resolved in versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, and 14.3.3 LTS.

Affected products

  • TYPO3 TYPO3 CMS < 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, 14.0.0-14.3.2

Timeline

  • 2026-06-09: advisory: Initial advisory published by TYPO3
  • 2026-06-12: disclosed: GHSA published and reviewed

References