CVE-2026-47343: TYPO3 CMS - Destructive Actions on File Mount Folders
Problem Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions.
Solution Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
Credits TYPO3 CMS thanks Arne Uplegger for reporting this issue, and TYPO3 security team member Elias Häußler for fixing it.
Resources TYPO3-CORE-SA-2026-007
Other sources
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 14.3.3 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 13.4.31 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 12.4.46 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 11.5.51 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 10.4.57
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47343?
CVE-2026-47343 has a high severity rating of 7.2 according to CVSS.
How can I fix CVE-2026-47343?
To fix CVE-2026-47343, you should upgrade to TYPO3 CMS versions 10.4.57 or 11.5.51 and above.
What types of attacks are possible due to CVE-2026-47343?
CVE-2026-47343 allows non-privileged backend users to perform unauthorized write actions such as moving, deleting, or renaming files in root file mount folders.
Which versions of TYPO3 CMS are affected by CVE-2026-47343?
CVE-2026-47343 affects TYPO3 CMS versions before 10.4.57, 11.0.0 through 11.5.50, and 12.0.0 through 12.2.0.
What is the impact of exploiting CVE-2026-47343?
Exploiting CVE-2026-47343 could lead to data loss or unauthorized modification of files by users without proper permissions.