Description
Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.
Published: 2026-06-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Backend users were able to move records to a different page without having edit permissions on the source page. This broken access control flaw, classified as CWE‑862, allows backend users lacking edit rights on a source page to relocate records to a new page, effectively bypassing the intended permissions model.

Affected Systems

TYPO3 CMS versions 13.0.0‑13.4.30 and 14.0.0‑14.3.2 are affected.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate impact level. The EPSS score of < 1% shows a very low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is through the web‑based backend interface, requiring only valid user credentials; no additional privileges or conditions are required.

Generated by OpenCVE AI on August 2, 2026 at 02:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update TYPO3 to a version later than 13.4.30 or 14.3.2 to apply the vendor’s official fix.
  • Restrict backend user permissions so that only authorized roles have edit rights to source pages, thereby enforcing proper access control.
  • Enable change‑audit logging for record movements to detect and respond to unauthorized actions.

Generated by OpenCVE AI on August 2, 2026 at 02:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qcmw-6rm2-5x78 TYPO3 CMS has Broken Access Control in its DataHandler
History

Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3. Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.

Tue, 09 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
Description Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3.
Title TYPO3 CMS - Broken Access Control in DataHandler
First Time appeared Typo3
Typo3 typo3
Weaknesses CWE-862
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Vendors & Products Typo3
Typo3 typo3
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-07-15T12:47:29.812Z

Reserved: 2026-05-19T12:49:25.966Z

Link: CVE-2026-47350

cve-icon Vulnrichment

Updated: 2026-06-09T13:50:25.316Z

cve-icon NVD

Status : Deferred

Published: 2026-06-09T11:16:52.860

Modified: 2026-06-09T13:46:50.540

Link: CVE-2026-47350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T02:15:03Z

Weaknesses