CVE-2026-49742 Details
Description
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
A broken access control vulnerability has been identified in the TYPO3 CMS Media Module, affecting versions 11.0.0 through 11.5.50, 12.0.0 through 12.4.45, 13.0.0 through 13.4.30, and 14.0.0 through 14.3.2. This vulnerability allows backend users with file download permissions to access and download sensitive files, such as log files, from the fallback storage of the file abstraction layer (FAL). The issue arises because the fallback storage paths are resolved relative to the server's document root, potentially exposing confidential information.
Users are advised to update TYPO3 to versions 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, or 14.3.3 LTS, all of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 9, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TYPO3/typo3/commit/ad636b6183843b57c758a1e12174a75093ac93c3 | TYPO3 | Source CodeVendor |
| https://github.com/TYPO3/typo3/commit/caa6b444d7ab1bdd1eb76a68004c8be73d98e6ae | TYPO3 | Source CodeVendor |
| https://typo3.org/security/advisory/typo3-core-sa-2026-013 | TYPO3 | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | TYPO3 |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 | >= 11.0.0, <= 11.5.50 (semver) >= 12.0.0, <= 12.4.45 (semver) >= 13.0.0, <= 13.4.30 (semver) >= 14.0.0, <= 14.3.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | TYPO3 |
Volerion