VYPR
Medium severityNVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-47352

CVE-2026-47352

Description

Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission checks, allowing access to files outside their permitted file mounts or storages. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cms-corePackagist
< 10.4.5710.4.57
typo3/cms-corePackagist
>= 11.0.0, < 11.5.5111.5.51
typo3/cms-corePackagist
>= 12.0.0, < 12.4.4612.4.46
typo3/cms-corePackagist
>= 13.0.0, < 13.4.3113.4.31
typo3/cms-corePackagist
>= 14.0.0, < 14.3.314.3.3
typo3/cms-backendPackagist
< 10.4.5710.4.57
typo3/cms-backendPackagist
>= 11.0.0, < 11.5.5111.5.51
typo3/cms-backendPackagist
>= 12.0.0, < 12.4.4612.4.46
typo3/cms-backendPackagist
>= 13.0.0, < 13.4.3113.4.31
typo3/cms-backendPackagist
>= 14.0.0, < 14.3.314.3.3

Affected products

2
  • TYPO3/Typo3references2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31, 14.0.0-14.3.3

Patches

Vulnerability mechanics

References

7

News mentions

1