CVE-2026-47346 Details
Description
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
A vulnerability exists in the TYPO3 CMS Form Framework (ext:form) that allows backend users with file write permissions to upload form definition files with mixed-case extensions, such as .FORM.YAML. This upload bypasses the Form Framework's standard restrictions. Once uploaded, these maliciously crafted form definition files can execute arbitrary SQL statements. This capability could be exploited to escalate privileges by creating administrative backend user accounts. The vulnerability affects TYPO3 CMS versions prior to 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, and 14.0.0-14.3.2.
Update TYPO3 to versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, or 14.3.3 LTS.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 9, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TYPO3/typo3/commit/2030617e6f273cee7b756c695f0a48a45a31eb47 | TYPO3 | Source CodeVendor |
| https://github.com/TYPO3/typo3/commit/eb2b2251d90339d3ab55df3d4c0378ae0c780b45 | TYPO3 | Source CodeVendor |
| https://typo3.org/security/advisory/typo3-core-sa-2026-008 | TYPO3 | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-178 | Improper Handling of Case Sensitivity | TYPO3 |
| CWE-862 | Missing Authorization | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 | >= 10.0.0, <= 10.4.56 (semver) >= 11.0.0, <= 11.5.50 (semver) >= 12.0.0, <= 12.4.45 (semver) >= 13.0.0, <= 13.4.30 (semver) >= 14.0.0, <= 14.3.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | TYPO3 |
Volerion