Executive brief
TYPO3 CMS, a popular web content management system, contains a security flaw in its form-building component. An authorized user with basic file upload permissions can bypass security restrictions to upload malicious configuration files. This allows an attacker to execute unauthorized database commands and create new administrator accounts, potentially leading to a full takeover of the website.
Technical details
A broken access control vulnerability exists in the TYPO3 Form Framework due to improper handling of case sensitivity (CWE-178) during file extension validation. Backend users with existing file write permissions can bypass upload restrictions by using mixed-case extensions (e.g., '.FORM.YAML') for form definition files. Once uploaded, these maliciously crafted YAML files can be processed to execute arbitrary SQL statements. This enables an attacker to perform privilege escalation, such as creating new administrative backend accounts. The vulnerability is patched in versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, and 14.3.3 LTS.
Affected products
- TYPO3 TYPO3 CMS < 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, 14.0.0-14.3.2
Timeline
- 2026-06-09: disclosed
- 2026-06-09: patched
- 2026-06-12: advisory
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-hwvq-2w67-rvxp
- https://github.com/TYPO3/typo3/commit/2030617e6f273cee7b756c695f0a48a45a31eb47
- https://github.com/TYPO3/typo3/commit/eb2b2251d90339d3ab55df3d4c0378ae0c780b45
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47346.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-008