Executive brief
TYPO3 CMS, a popular enterprise content management system, contains a security flaw in its Media Module. Authenticated users with basic file download permissions can bypass intended restrictions to download sensitive system files, such as server logs, from the server's root directory. This could lead to the exposure of confidential configuration data or system information, potentially aiding further attacks.
Technical details
A broken access control vulnerability exists in the TYPO3 Media Module's interaction with the File Abstraction Layer (FAL). Backend users with existing file download permissions can exploit the 'fallback storage' mechanism, which incorrectly resolves file paths relative to the server's document root rather than restricted media directories. This allows for a path traversal-style attack where sensitive files, including system logs and configuration files, can be retrieved by an attacker with low-level backend privileges. The issue is resolved in TYPO3 versions 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, and 14.3.3 LTS.
Affected products
- TYPO3 TYPO3 CMS 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, 14.0.0-14.3.2
Timeline
- 2026-06-09: disclosed
- 2026-06-09: patched
- 2026-06-12: advisory
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-chm7-4vch-h8vr
- https://github.com/TYPO3/typo3/commit/ad636b6183843b57c758a1e12174a75093ac93c3
- https://github.com/TYPO3/typo3/commit/caa6b444d7ab1bdd1eb76a68004c8be73d98e6ae
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-49742.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-013