Executive brief
TYPO3 CMS is a popular enterprise content management system. A security flaw in its data handling component allowed authorized backend users to move content records between pages even if they did not have permission to edit the original source page. This could lead to unauthorized modification of website structure or content organization by users with limited access.
Technical details
A broken access control vulnerability (CWE-862) exists in the TYPO3 DataHandler's moveRecord() function. Following a refactoring in a previous version, a critical authorization check was omitted, failing to verify if a backend user possessed edit permissions on the source page before executing a move operation. An authenticated backend user with low privileges can exploit this to relocate records to different pages across the CMS. The issue is resolved in TYPO3 versions 13.4.31 and 14.3.3 by re-implementing the missing permission check.
Affected products
- TYPO3 TYPO3 CMS >= 13.0.0, < 13.4.31; >= 14.0.0, < 14.3.3
Timeline
- 2026-06-09: advisory: Initial advisory published by TYPO3 and NVD
- 2026-06-12: disclosed: GitHub Advisory published
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-qcmw-6rm2-5x78
- https://github.com/TYPO3/typo3/commit/195356996a60e40aeb2cd3e45a5f5c8940d5e116
- https://github.com/TYPO3/typo3/commit/c9898d2e67608eda78f8bd1f06ee9cf05a872a56
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47350.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-012