VYPR
Low severityNVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-49738

CVE-2026-49738

Description

The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be incorrectly accepted as valid when the project root was /var/www/html. Administrator users with access to the File Abstraction Layer were able to create new file storage definitions pointing to directories outside the project root, bypassing this path check. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typo3/cms-corePackagist
< 10.4.5710.4.57
typo3/cms-corePackagist
>= 11.0.0, < 11.5.5111.5.51
typo3/cms-corePackagist
>= 12.0.0, < 12.4.4612.4.46
typo3/cms-corePackagist
>= 13.0.0, < 13.4.3113.4.31
typo3/cms-corePackagist
>= 14.0.0, < 14.3.314.3.3

Affected products

2
  • TYPO3/Typo3references2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31, 14.0.0-14.3.3

Patches

Vulnerability mechanics

References

7

News mentions

1