{"id":"CVE-2026-47346","aliases":["GHSA-hwvq-2w67-rvxp"],"url":"https://o3.security/vulnerability/CVE-2026-47346","summary":"TYPO3 CMS - Broken Access Control in Form Framework","details":"### Problem\nBackend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., `.FORM.YAML`) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts.\n\n### Solution\nUpdate to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.\n\n### Credits\nTYPO3 CMS thanks Alexander Künzl for reporting this issue, and to TYPO3 core & security team members Oliver Hader and Benjamin Franzke for fixing it.\n\n### Resources\n* [TYPO3-CORE-SA-2026-008](https://typo3.org/security/advisory/typo3-core-sa-2026-008)","published":"2026-06-09T10:50:21.934Z","modified":"2026-08-12T03:51:23.096571957Z","cvss":null,"epss":{"score":0.00253,"percentile":0.16945,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"10.4.57"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"11.5.51"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.46"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"13.4.31"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"14.3.3"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"10.4.57"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"11.5.51"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"12.4.46"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"13.4.31"},{"ecosystem":"Packagist","name":"typo3/cms-form","fixedVersion":"14.3.3"}],"fix":{"url":"https://github.com/TYPO3/typo3/commit/2030617e6f273cee7b756c695f0a48a45a31eb47","label":"TYPO3/typo3@2030617"},"references":[{"type":"WEB","url":"https://packagist.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47346.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47346"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2026-008"},{"type":"FIX","url":"https://github.com/TYPO3/typo3/commit/2030617e6f273cee7b756c695f0a48a45a31eb47"},{"type":"FIX","url":"https://github.com/TYPO3/typo3/commit/eb2b2251d90339d3ab55df3d4c0378ae0c780b45"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-hwvq-2w67-rvxp"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47346.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:23.096571957Z"}}