PT-2026-47749 · Typo3 Association · Typo3/Cms

·

CVE-2026-49742

·

Published

2026-06-09

·

Updated

2026-06-12

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TYPO3 CMS versions 11.0.0 through 11.5.50 TYPO3 CMS versions 12.0.0 through 12.4.45 TYPO3 CMS versions 13.0.0 through 13.4.30 TYPO3 CMS versions 14.0.0 through 14.3.2
Description Backend users with file download permissions can download files from the fallback storage of the file abstraction layer (FAL) through the Media Module. Because the fallback storage resolves paths relative to the server's document root, this can lead to the exposure of sensitive files, such as log files.
Recommendations Update TYPO3 CMS versions 11.0.0 through 11.5.50 to a version later than 11.5.50. Update TYPO3 CMS versions 12.0.0 through 12.4.45 to a version later than 12.4.45. Update TYPO3 CMS versions 13.0.0 through 13.4.30 to a version later than 13.4.30. Update TYPO3 CMS versions 14.0.0 through 14.3.2 to a version later than 14.3.2.

Exploit

Fix

Path traversal

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49742
GHSA-CHM7-4VCH-H8VR

Affected Products

Typo3/Cms