CVE-2026-19418: TYPO3 CMS - Broken Access Control in Backend and Install Tool
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 https://news.typo3.com/security/advisory/typo3-core-sa-2020-006 ( CVE-2020-11069 https://www.cve.org/CVERecord ) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Ensure the TYPO3-CORE-SA-2020-006 referrer enforcement logic is applied in a way that correctly distinguishes requests originating from backend/Install Tool vs requests originating from other pages on the same domain; the ineffective behavior in v13.0 is because the comparison directory became the site root.
TYPO3 CMS Referrer enforcement introduced with TYPO3-CORE-SA-2020-006 = Make it effective again despite backend/Install Tool being served from the site's main entry script in TYPO3 v13.0 - Compensating control
Until the referrer enforcement is restored, prevent requests from TYPO3 instance own domains initiated by untrusted scripts from reaching backend routes and Install Tool endpoints (e.g., block such cross-origin/script-initiated requests at the network layer using appropriate firewall/ACL rules to restrict access to backend/Install Tool paths).