Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-85400 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-266Incorrect Privilege AssignmentTYPO3
CWE-862Missing AuthorizationTYPO3

Affected Products

ProductVersions
TYPO3
>= 14.2.0, <= 14.3.6 (semver)

CPE

  • cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 14.3.7moderate effort
  • Mitigation:low effort

    Existing scheduler tasks configured to execute the "configuration:*" commands no longer work. Use alternative execution methods to perform scheduled configuration updates, such as implementing custom cronjobs.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-85400
NVD Published Date:
Sep 8, 2026
NVD Last Modified:
Sep 8, 2026
Source:
TYPO3
CVE-2026-85400 Details - Not Deferred