CVE-2026-11607: TYPO3 CMS - Broken Access Control in Form Framework
Problem Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts.
Solution Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
Credits TYPO3 CMS thanks “Ethan” for reporting this issue, and TYPO3 core & security team member Oliver Hader for fixing it.
Resources TYPO3-CORE-SA-2026-019
Other sources
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
— MITRE
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-formto a version that resolves this vulnerability.Fixed in 14.3.3 - Upgrade
Upgrade
composer/typo3/cms-formto a version that resolves this vulnerability.Fixed in 13.4.31 - Upgrade
Upgrade
composer/typo3/cms-formto a version that resolves this vulnerability.Fixed in 12.4.46 - Upgrade
Upgrade
composer/typo3/cms-formto a version that resolves this vulnerability.Fixed in 11.5.51 - Upgrade
Upgrade
composer/typo3/cms-formto a version that resolves this vulnerability.Fixed in 10.4.57 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 14.3.3 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 13.4.31 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 12.4.46 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 11.5.51 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 10.4.57 - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 10.4.57 ELTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 11.5.51 ELTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 12.4.46 ELTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 13.4.31 LTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 14.3.3 LTS - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch TYPO3-CORE-SA-2026-019
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11607?
CVE-2026-11607 has a high severity rating of 7.6 on the CVSS scale.
How do I fix CVE-2026-11607?
To mitigate CVE-2026-11607, ensure that access controls are properly implemented for form definitions so that only files ending with .form.yaml are processed.
What systems are affected by CVE-2026-11607?
CVE-2026-11607 affects the Typo3 CMS, particularly the Form Framework module.
What kind of attacks can result from CVE-2026-11607?
CVE-2026-11607 allows attackers to execute arbitrary SQL statements, potentially compromising the database.
When was CVE-2026-11607 published?
CVE-2026-11607 was published on June 9, 2026.