Executive brief
TYPO3 CMS is a professional content management system used to build and manage websites. A security flaw in the system's clipboard functionality allowed authorized backend users to access information about files and records they were not supposed to see. This could lead to the exposure of sensitive internal data or administrative details to users with limited permissions.
Technical details
A broken access control vulnerability (CWE-862) exists in the TYPO3 CMS Media and Clipboard modules. Backend users with low privileges could insert arbitrary records and files into the system clipboard without the application performing proper read permission validation. This flaw allows an authenticated attacker to gather metadata or information about sensitive records and files that should be restricted based on their assigned roles. The issue is resolved in TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, and 14.3.3 LTS.
Affected products
- TYPO3 TYPO3 CMS < 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, 14.0.0-14.3.2
Timeline
- 2026-06-09: advisory: Initial advisory published by TYPO3 and NVD
- 2026-06-12: patched: GitHub Advisory Database entry updated with patch details
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-q93m-25xv-94hh
- https://github.com/TYPO3/typo3/commit/2740707563343d78184c0b7c6303a7484553d7f3
- https://github.com/TYPO3/typo3/commit/932fbb9fcea25094e8bcc0f0ec5aab56b1d92451
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47351.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-014