CVE-2026-85400 Details
Description
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.
A vulnerability exists in TYPO3 CMS versions 14.2.0 prior to 14.3.6, allowing backend administrators without system maintainer privileges to schedule and execute configuration-related commands. This unauthorized access enabled them to modify system-wide configuration arbitrarily, a capability typically reserved for system maintainers. As a result, these administrators could potentially escalate their privileges to gain system maintainer rights or cause a denial-of-service condition. Exploitation of this vulnerability requires an administrator-level backend user account.
Users are advised to update TYPO3 to version 14.3.7 LTS, which addresses this vulnerability by disallowing the scheduled execution of the affected configuration commands. Existing scheduler tasks using these commands will no longer function and should be removed. If needed, schedule configuration updates can be managed through custom cronjobs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TYPO3/typo3/commit/b8abe36978c63a0625aee70df078895216e7ee27 | TYPO3 | Source CodeVendor |
| https://github.com/TYPO3/typo3/commit/e15da7ba0218532240578b471152f76c13cb4154 | TYPO3 | Source CodeVendor |
| https://news.typo3.com/security/advisory/typo3-core-sa-2026-023 | TYPO3 | AdvisoryRemedyVendor |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| TYPO3 | >= 14.2.0, <= 14.3.6 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | TYPO3 |
Volerion