CVE-2026-104476: Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Backdrop CMSto a version that resolves this vulnerability.Fixed in 1.35.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Backdrop CMS installations before 1.35.1 may be exposed if a configuration export archive has been generated and left on the server after transfer. The archive can contain the full site configuration, including sensitive settings.
Does exploitation require an account or user interaction?
No. The issue is described as exploitable by unauthenticated attackers, with no user interaction required. Exploitation depends on an export archive being present and retrievable on the server.
How can I determine whether sensitive data may already be exposed?
Review whether users with configuration export permission have generated configuration export archives and whether those archives remained on the server after transfer. Any retained archive should be treated as potentially downloadable by an unauthenticated party.
What should be done if upgrading is not immediately possible?
Remove configuration export archives left on the server after transfer and prevent them from remaining in web-accessible locations. Because exported archives may include sensitive settings, assess and rotate affected secrets where exposure is suspected.