CVE-2026-19418: TYPO3 CMS - Broken Access Control in Backend and Install Tool

Published Aug 11, 2026
·
Updated

Problem The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Admin Tool applications from the site's main entry script instead of the dedicated typo3/ directory.

Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints.

Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session.

Solution Update to TYPO3 versions 13.4.34 LTS, 14.3.6 LTS that fix the problem described.

Credits Thanks to Hổ Cao Từ for reporting this issue, and to TYPO3 core & security team member Benjamin Franzke for fixing it.

Other sources

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory.

Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints.

Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5.

— MITRE

Affected Software

4 affected componentsFixes available
Typo3 TYPO3 CMS>=13.0.0<=13.4.33
Typo3 TYPO3 CMS>=14.0.0<=14.3.5
composer/typo3/cms-core>=14.0.0<14.3.6
14.3.6
composer/typo3/cms-backend>=13.0.0<13.4.34
13.4.34

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/typo3/cms-core to a version that resolves this vulnerability.

    Fixed in 14.3.6
  2. Upgrade

    Upgrade composer/typo3/cms-backend to a version that resolves this vulnerability.

    Fixed in 13.4.34
  3. Upgrade

    Upgrade TYPO3 CMS to a version that resolves this vulnerability.

    Fixed in 13.4.34 LTS
  4. Upgrade

    Upgrade TYPO3 CMS to a version that resolves this vulnerability.

    Fixed in 14.3.6 LTS

Event History

Aug 11, 2026
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Sep 1, 2026
Advisory Published
via GitHub·09:31 PM
Data Sourced
via GitHub·09:31 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-19418?

CVE-2026-19418 has a severity score of 60, indicating a moderate risk level.

2

How do I fix CVE-2026-19418?

To fix CVE-2026-19418, upgrade to the latest version of TYPO3 CMS that addresses the broken access control issues.

3

What causes CVE-2026-19418 in TYPO3?

CVE-2026-19418 is caused by ineffective referrer enforcement in the TYPO3 backend and Install Tool applications.

4

What is the impact of CVE-2026-19418?

The impact of CVE-2026-19418 allows unauthorized access to the TYPO3 backend and Install Tool, potentially compromising the site.

5

Is CVE-2026-19418 related to previous vulnerabilities?

Yes, CVE-2026-19418 is related to CVE-2020-11069, where referrer enforcement was previously introduced but became ineffective.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203