TYPO3 CMS Backend API Broken Access Control Vulnerability

Vulnerability

A broken access control vulnerability has been identified in TYPO3 CMS Backend API. Authenticated backend users could access file metadata through various API routes without proper permission checks. This flaw allowed users to retrieve files outside their authorized file mounts or storage areas. The vulnerability affects TYPO3 CMS versions prior to 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, and 14.0.0-14.3.2.

Impact

Exploitation of this vulnerability could lead to unauthorized access to file metadata and files outside of a user's permitted storage areas.

Reproduction

To reproduce this vulnerability, an authenticated backend user can send requests to the affected Backend API routes that handle file metadata. The API will respond with file information without verifying if the user has the right permissions to access those files, potentially including files from unauthorized storage areas.

Remediation

Users are advised to update TYPO3 to versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, or 14.3.3 LTS, all of which address this vulnerability.

Added: Jun 9, 2026, 11:25 AM
Updated: Jun 9, 2026, 11:25 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
0.6
exploitability
6.4
remediation
7.7
relevance
9.4
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.