CVE-2026-19418: TYPO3 CMS - Broken Access Control in Backend and Install Tool

Published Aug 11, 2026
·
Updated

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 https://news.typo3.com/security/advisory/typo3-core-sa-2020-006 ( CVE-2020-11069 https://www.cve.org/CVERecord ) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5.

Affected Software

1 affected component
Typo3 TYPO3 CMS>=13.0.0<=13.4.33, >=14.0.0<=14.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure the TYPO3-CORE-SA-2020-006 referrer enforcement logic is applied in a way that correctly distinguishes requests originating from backend/Install Tool vs requests originating from other pages on the same domain; the ineffective behavior in v13.0 is because the comparison directory became the site root.

    TYPO3 CMS Referrer enforcement introduced with TYPO3-CORE-SA-2020-006 = Make it effective again despite backend/Install Tool being served from the site's main entry script in TYPO3 v13.0
  2. Compensating control

    Until the referrer enforcement is restored, prevent requests from TYPO3 instance own domains initiated by untrusted scripts from reaching backend routes and Install Tool endpoints (e.g., block such cross-origin/script-initiated requests at the network layer using appropriate firewall/ACL rules to restrict access to backend/Install Tool paths).

Event History

Aug 11, 2026
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203