PT-2026-108731 · Backdrop Cms · Backdrop

CVE-2026-107914

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. NOTE: CVE-2026-107914 refers to the vulnerability in which config.admin.inc does not ensure that a file unmanaged delete operation occurs. Therefore, many archives could persist: config.tar.gz, config 0.tar.gz, config 1.tar.gz, etc. There is a separate config.module issue that could allow remote access by an anonymous user, but only for the one filename config.tar.gz.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107914

Affected Products

Backdrop