{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/typo3-cms-13.0.0---13.4.33/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TYPO3 CMS (13.0.0 - 13.4.33)","TYPO3 CMS (14.0.0 - 14.3.5)"],"_cs_severities":["medium"],"_cs_tags":["web-application","cms","vulnerability","cve-2026-19418"],"_cs_type":"advisory","_cs_vendors":["TYPO3"],"content_html":"\u003cp\u003eTYPO3 CMS is vulnerable to a broken access control flaw identified as CVE-2026-19418, affecting versions 13.0.0 through 13.4.33 and 14.0.0 through 14.3.5. This issue stems from a regression introduced when TYPO3 v13.0 transitioned to serving backend and Install Tool applications from the site root entry script rather than a dedicated directory. The application relies on referrer validation to verify the origin of administrative requests. Because the site root is now the origin for both frontend and backend requests, the validation logic fails to distinguish between them. An attacker capable of executing arbitrary JavaScript on a frontend domain, such as through a Cross-Site Scripting (XSS) vulnerability, can craft Fetch or XHR requests that bypass these origin checks. Consequently, the attacker can invoke sensitive backend or Install Tool endpoints using the session privileges of an authenticated administrator, leading to potential site takeover or configuration modification.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to abuse an authenticated administrator's session to execute privileged administrative operations. This can lead to unauthorized changes to the TYPO3 instance configuration, modification of content, or full administrative takeover of the CMS, depending on the available functions within the backend and Install Tool.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade TYPO3 installations to version 13.4.34 LTS or 14.3.6 LTS to resolve CVE-2026-19418.\u003c/li\u003e\n\u003cli\u003eAudit all public-facing pages for potential Cross-Site Scripting (XSS) vulnerabilities, as these serve as the primary delivery vector for this access control bypass.\u003c/li\u003e\n\u003cli\u003eImplement strict Content Security Policy (CSP) headers to restrict where the browser can load resources and where it can send asynchronous requests, mitigating the risk of unauthorized XHR/Fetch invocations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T00:00:07Z","date_published":"2026-09-02T00:00:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-typo3-broken-access/","summary":"TYPO3 CMS versions 13.0.0 through 13.4.33 and 14.0.0 through 14.3.5 contain a broken access control vulnerability (CVE-2026-19418) that allows attackers to perform unauthorized actions by abusing ineffective referrer enforcement.","title":"Broken Access Control in TYPO3 CMS Backend and Install Tool","url":"https://feed.craftedsignal.io/briefs/2026-09-typo3-broken-access/"}],"language":"en","title":"CraftedSignal Threat Feed - TYPO3 CMS (13.0.0 - 13.4.33)","version":"https://jsonfeed.org/version/1.1"}