CVE-2026-47349: TYPO3 CMS - Broken Access Control in Recycler
Problem Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify.
Solution Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
Credits TYPO3 CMS thanks Hyunseo Shin for reporting this issue, and TYPO3 security team member Elias Häußler for fixing it.
Resources TYPO3-CORE-SA-2026-011
Other sources
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
— MITRE
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/typo3/cms-recyclerto a version that resolves this vulnerability.Fixed in 14.3.3 - Upgrade
Upgrade
composer/typo3/cms-recyclerto a version that resolves this vulnerability.Fixed in 13.4.31 - Upgrade
Upgrade
composer/typo3/cms-recyclerto a version that resolves this vulnerability.Fixed in 12.4.46 - Upgrade
Upgrade
composer/typo3/cms-recyclerto a version that resolves this vulnerability.Fixed in 11.5.51 - Upgrade
Upgrade
composer/typo3/cms-recyclerto a version that resolves this vulnerability.Fixed in 10.4.57 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 14.3.3 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 13.4.31 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 12.4.46 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 11.5.51 - Upgrade
Upgrade
composer/typo3/cms-coreto a version that resolves this vulnerability.Fixed in 10.4.57 - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 10.4.57 ELTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 11.5.51 ELTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 12.4.46 ELTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 13.4.31 LTS - Upgrade
Upgrade
TYPO3 CMSto a version that resolves this vulnerability.Fixed in 14.3.3 LTS
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47349?
CVE-2026-47349 has a severity rating of medium, with a CVSS score of 5.3.
How do I fix CVE-2026-47349?
To fix CVE-2026-47349, upgrade TYPO3 CMS to versions 10.4.57, 11.5.51, 12.4.46, or later.
What issues are caused by CVE-2026-47349?
CVE-2026-47349 allows unauthorized backend users to restore soft-deleted records they shouldn't have access to.
Which TYPO3 CMS versions are affected by CVE-2026-47349?
CVE-2026-47349 affects TYPO3 CMS versions prior to 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31, and 14.0.0-14.3.3.
Who is impacted by CVE-2026-47349?
Backend users with access to the Recycler module are impacted by CVE-2026-47349.