High severity7.5NVD Advisory· Published Apr 21, 2026· Updated May 5, 2026
CVE-2026-6553
CVE-2026-6553
Description
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/cms-backendPackagist | >= 14.2.0, < 14.3.0 | 14.3.0 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/TYPO3/typo3/commit/9a6e913f70767f63b322ae3e2d2f4e302624c291nvdPatchWEB
- github.com/advisories/GHSA-xvv6-p4wf-mvx7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-6553ghsaADVISORY
- typo3.org/security/advisory/typo3-core-sa-2026-005nvdVendor AdvisoryWEB
- github.com/TYPO3/typo3/security/advisories/GHSA-xvv6-p4wf-mvx7ghsaWEB
News mentions
0No linked articles in our index yet.