PT-2026-70078 · Typo3 Association · Typo3/Cms

·

CVE-2026-19418

·

Published

2026-08-11

·

Updated

2026-09-01

CVSS v4.0

7.3

High

VectorAV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TYPO3 CMS versions 13.0.0 through 13.4.33 TYPO3 CMS versions 14.0.0 through 14.3.5
Description Referrer enforcement became ineffective because the backend and Install Tool applications are served from the site's main entry script rather than a dedicated directory. The system determines if a request originated from the backend or Install Tool by comparing the referrer against the entry script directory, which is now the site root. Consequently, requests from any script on the instance's own domains, such as frontend pages, are accepted by backend routes and Install Tool endpoints. An attacker capable of executing JavaScript on these domains could use Fetch or XHR to invoke these endpoints using the privileges of an authenticated user's session.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19418
GHSA-4F2F-JR2M-J7P4
GHSA-68JX-F42C-7599

Affected Products

Typo3/Cms