CVE-2026-47352

Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
CVSS

No CVSS.

Configurations

No configuration.

History

09 Jun 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 11:16

Updated : 2026-06-17 10:54


NVD link : CVE-2026-47352

Mitre link : CVE-2026-47352

CVE.ORG link : CVE-2026-47352


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization