Executive brief
TYPO3 CMS, a popular enterprise content management system, contains a security flaw in its administrative backend. This vulnerability allows logged-in staff members to view information about files they are not authorized to see, potentially exposing sensitive metadata or file structures. Organizations should update to the latest patched versions to ensure internal access controls are properly enforced.
Technical details
A missing authorization vulnerability (CWE-862) exists in several TYPO3 Backend API routes. The root cause is a failure to perform proper permission checks when retrieving file metadata, allowing an authenticated backend user to bypass configured file mounts or storage restrictions. An attacker with low-level backend privileges can exploit this over the network to access metadata for files they should not be able to view. The issue is resolved in TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, and 14.3.3 LTS.
Affected products
- TYPO3 TYPO3 CMS < 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, 14.0.0-14.3.2
Timeline
- 2026-06-09: disclosed: Initial disclosure by TYPO3 and NVD publication
- 2026-06-12: advisory: GitHub Advisory published and reviewed
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-2j54-93q2-3hjq
- https://github.com/TYPO3/typo3/commit/17a3b7830d5931725db5fdab0cfc76d479884c96
- https://github.com/TYPO3/typo3/commit/bfe7c354168f467726020ed49299dd209a455719
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47352.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-015