Back

HIGH

TYPO3 CMS Stores Cleartext Password in User Settings Module

Published Apr 21, 2026

Description

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TYPO3
Published Apr 21, 2026
Updated Apr 21, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Apr 21, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner TYPO3
Published Apr 21, 2026
Updated Apr 21, 2026
Exploited since n/a
EUVD-2026-24081 GHSA-XVV6-P4WF-MVX7