Description
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated attacker can download configuration export archives that remain on the server, exposing the complete site configuration and sensitive data. The weakness is a classic Information Disclosure flaw (CWE‑200) that allows third parties to read confidential information without authenticating.

Affected Systems

Backdrop CMS versions earlier than 1.35.1 are affected. The vulnerability applies to all installations of the Backdrop CMS product for which configuration export archives are left accessible on the web server.

Risk and Exploitability

The vulnerability scores 8.2 on CVSS, indicating high severity. The EPSS score is not available, but the impact of exposing the entire configuration suggests that attackers could easily harvest this data without needing any credentials. The issue is not listed in the CISA KEV catalog. Attackers can exploit the flaw simply by accessing the export archive URL through a web browser or with a script, making the attack vector publicly reachable.

Generated by OpenCVE AI on October 3, 2026 at 00:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Backdrop CMS patch that includes the 1.35.1 update or later, ensuring the configuration export feature is properly secured.
  • Delete any existing configuration export archives from the web server to remove exposed files.
  • Adjust file system permissions and web server configuration so that export archives cannot be publicly accessed, and restrict the configuration export functionality to authorized users only.

Generated by OpenCVE AI on October 3, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
Title Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive
First Time appeared Backdropcms
Backdropcms backdrop
Weaknesses CWE-200
CPEs cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:*
Vendors & Products Backdropcms
Backdropcms backdrop
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Backdropcms Backdrop
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T23:28:46.804Z

Reserved: 2026-10-02T00:55:58.388Z

Link: CVE-2026-104476

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T00:16:35.747

Modified: 2026-10-03T00:16:35.747

Link: CVE-2026-104476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T00:30:19Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor