Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6. | |
| Title | TYPO3 CMS - Missing Authorization in lowlevel commands | |
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Weaknesses | CWE-266 CWE-862 |
|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-09-08T09:18:40.983Z
Reserved: 2026-09-03T18:20:16.551Z
Link: CVE-2026-85400
No data.
Status : Received
Published: 2026-09-08T10:17:14.060
Modified: 2026-09-08T10:17:14.060
Link: CVE-2026-85400
No data.
OpenCVE Enrichment
Updated: 2026-09-08T10:30:05Z
