PT-2026-108731 · Backdrop Cms · Backdrop
CVE-2026-107914
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. NOTE: CVE-2026-107914 refers to the vulnerability in which config.admin.inc does not ensure that a file unmanaged delete operation occurs. Therefore, many archives could persist: config.tar.gz, config 0.tar.gz, config 1.tar.gz, etc. There is a separate config.module issue that could allow remote access by an anonymous user, but only for the one filename config.tar.gz.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Backdrop