MEDIUM
TYPO3 CMS - Broken Access Control in Clipboard
Published Jun 9, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.41%
Description
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2.
Affected products
-
- Version 10.4.0StatusaffectedConstraints<13.4.31
- Version 14.0.0StatusaffectedConstraints<14.3.3
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35398 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47351.yaml
- https://github.com/TYPO3/typo3/commit/2740707563343d78184c0b7c6303a7484553d7f3 patch
- https://github.com/TYPO3/typo3/commit/932fbb9fcea25094e8bcc0f0ec5aab56b1d92451 patch
- https://github.com/TYPO3/typo3/security/advisories/GHSA-q93m-25xv-94hh
- https://github.com/advisories/GHSA-q93m-25xv-94hh Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-47351
- https://typo3.org/security/advisory/typo3-core-sa-2026-014 vendor-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TYPO3
Published Jun 9, 2026
Updated Jun 11, 2026
Reserved May 19, 2026
Link CVE-2026-47351
CISA Vulnrichment
Updated Jun 9, 2026
ENISA EUVD
EUVD-2026-35398 GHSA-Q93M-25XV-94HH Assigner TYPO3
Published Jun 9, 2026
Updated Jun 11, 2026
Exploited since n/a
Link EUVD-2026-35398