CVE-2026-47350
published 2026-06-09CVE-2026-47350: Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions…
PriorityP430medium5.3CVSS 4.0
AVNACLATNPRLUINVCNVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.24%
14.7th percentile
Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.30 and 14.0.0-14.3.2.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms-core | >= 13.0.0 < 13.4.31 | 13.4.31 |
| typo3 | cms-core | >= 14.0.0 < 14.3.3 | 14.3.3 |
| typo3 | typo3_cms | >= 13.0.0 < 13.4.31 | 13.4.31 |
| typo3 | typo3_cms | >= 14.0.0 < 14.3.3 | 14.3.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TYPO3 CMS up to 13.4.30/14.3.2 authorization (WID-SEC-2026-1835)
vuldb·2026-07-17·CVSS 5.3
CVE-2026-47350 [MEDIUM] TYPO3 CMS up to 13.4.30/14.3.2 authorization (WID-SEC-2026-1835)
A vulnerability classified as problematic was found in TYPO3 CMS up to 13.4.30/14.3.2. Affected by this issue is some unknown functionality. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-47350. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
TYPO3 CMS has Broken Access Control in its DataHandler
ghsa·2026-06-12
CVE-2026-47350 [MEDIUM] CWE-862 TYPO3 CMS has Broken Access Control in its DataHandler
TYPO3 CMS has Broken Access Control in its DataHandler
### Problem
Backend users were able to move records to a different page without having edit permissions on the source page.
### Solution
Update to TYPO3 versions 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
### Credits
TYPO3 CMS thanks Hyunseo Shin for reporting this issue, and TYPO3 security team member Torben Hansen for fixing it.
### Resources
* [TYPO3-CORE-SA-2026-012](https://typo3.org/security/advisory/typo3-core-sa-2026-012)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-09
Published