CVE-2026-11607
published 2026-06-09CVE-2026-11607: Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the…
PriorityP350high7.6CVSS 4.0
AVNACLATPPRLUINVCHVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.24%
14.7th percentile
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms-core | >= 0 < 10.4.57 | 10.4.57 |
| typo3 | cms-core | >= 11.0.0 < 11.5.51 | 11.5.51 |
| typo3 | cms-core | >= 12.0.0 < 12.4.46 | 12.4.46 |
| typo3 | cms-core | >= 13.0.0 < 13.4.31 | 13.4.31 |
| typo3 | cms-core | >= 14.0.0 < 14.3.3 | 14.3.3 |
| typo3 | cms-form | >= 0 < 10.4.57 | 10.4.57 |
| typo3 | cms-form | >= 11.0.0 < 11.5.51 | 11.5.51 |
| typo3 | cms-form | >= 12.0.0 < 12.4.46 | 12.4.46 |
| typo3 | cms-form | >= 13.0.0 < 13.4.31 | 13.4.31 |
| typo3 | cms-form | >= 14.0.0 < 14.3.3 | 14.3.3 |
| typo3 | typo3_cms | < 10.4.57 | 10.4.57 |
| typo3 | typo3_cms | >= 11.0.0 < 11.5.51 | 11.5.51 |
| typo3 | typo3_cms | >= 12.0.0 < 12.4.46 | 12.4.46 |
| typo3 | typo3_cms | >= 13.0.0 < 13.4.31 | 13.4.31 |
| typo3 | typo3_cms | >= 14.0.0 < 14.3.3 | 14.3.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TYPO3 CMS up to 14.3.2 form.yaml authorization (EUVD-2026-35391 / WID-SEC-2026-1835)
vuldb·2026-06-13·CVSS 7.6
CVE-2026-11607 [HIGH] TYPO3 CMS up to 14.3.2 form.yaml authorization (EUVD-2026-35391 / WID-SEC-2026-1835)
A vulnerability identified as critical has been detected in TYPO3 CMS up to 10.4.56/11.5.50/12.4.45/13.4.30/14.3.2. The impacted element is an unknown function of the file form.yaml. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-11607. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
TYPO3 CMS has Broken Access Control in its Form Framework
ghsa·2026-06-12
CVE-2026-11607 [HIGH] CWE-862 TYPO3 CMS has Broken Access Control in its Form Framework
TYPO3 CMS has Broken Access Control in its Form Framework
### Problem
Backend users with access to the Form Framework were able to use files not ending in `.form.yaml` as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts.
### Solution
Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
### Credits
TYPO3 CMS thanks “Ethan” for reporting this issue, and TYPO3 core & security team member Oliver Hader for fixing it.
### Resources
* [TYPO3-CORE-SA-2026-019](https://typo3.org/security/advisory/typo3-core-sa-2
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published