HIGH
TYPO3 CMS Stores Cleartext Password in User Settings Module
Published Apr 21, 2026
7.3
HIGHCVSS 4.0
EPSS 0.27%
Description
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
Affected products
-
- Version 14.2.0StatusaffectedConstraints<14.3.0
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24081 Advisory
- https://github.com/TYPO3/typo3/commit/9a6e913f70767f63b322ae3e2d2f4e302624c291 patch
- https://github.com/TYPO3/typo3/security/advisories/GHSA-xvv6-p4wf-mvx7
- https://github.com/advisories/GHSA-xvv6-p4wf-mvx7 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-6553
- https://typo3.org/security/advisory/typo3-core-sa-2026-005 vendor-advisoryVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TYPO3
Published Apr 21, 2026
Updated Apr 21, 2026
Reserved Apr 17, 2026
Link CVE-2026-6553
CISA Vulnrichment
Updated Apr 21, 2026
ENISA EUVD
EUVD-2026-24081 GHSA-XVV6-P4WF-MVX7 Assigner TYPO3
Published Apr 21, 2026
Updated Apr 21, 2026
Exploited since n/a
Link EUVD-2026-24081