Description
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
Published: 2026-06-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in TYPO3 CMS enables backend users who can reach the Recycler module to restore soft‑deleted records on pages or tables that they are not authorized to modify. By bypassing built‑in deletion safeguards, an attacker can alter content and potentially leak or corrupt data, violating both data integrity and privacy rules.

Affected Systems

TYPO3 CMS versions earlier than 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2 are impacted. The vulnerability resides in the Recycler module of these releases.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is 0.00238 (less than 1%) and the vulnerability is not listed in CISA KEV, suggesting low but non-zero exploitation probability. An attacker must first possess authenticated backend access and the privilege to use the Recycler module; only then can they craft a request to restore a soft‑deleted record, effectively elevating their capability to modify content they should not control.

Generated by OpenCVE AI on July 21, 2026 at 19:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TYPO3 CMS to a version that includes the fix: 10.4.57 or later, 11.5.50 or later, 12.4.45 or later, 13.4.30 or later, or 14.3.2 or later.
  • Restrict access to the Recycler module so that only authorized staff with appropriate permissions can use it, ensuring that backend user roles do not overlap with content modification rights.
  • Temporarily disable the restore functionality for non‑admin users in the CMS configuration until a patch is applied.

Generated by OpenCVE AI on July 21, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f34x-rx2w-7pm3 TYPO3 CMS has Broken Access Control in the Recycler Module
History

Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3. Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

Tue, 09 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Description Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
Title TYPO3 CMS - Broken Access Control in Recycler
First Time appeared Typo3
Typo3 typo3
Weaknesses CWE-862
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Vendors & Products Typo3
Typo3 typo3
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-07-15T12:47:07.699Z

Reserved: 2026-05-19T12:49:25.966Z

Link: CVE-2026-47349

cve-icon Vulnrichment

Updated: 2026-06-09T13:51:19.046Z

cve-icon NVD

Status : Deferred

Published: 2026-06-09T11:16:52.720

Modified: 2026-06-09T13:46:50.540

Link: CVE-2026-47349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T19:15:03Z

Weaknesses