CVE-2026-104476 PUBLISHED

Backdrop CMS before 1.35.1 Information Disclosure via Configuration Export Archive

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor backdrop
Product backdrop
Versions Default: unaffected
  • affected from 0 to 1.35.1 (excl.)
  • Version 1.35.1 is unaffected

Credits

  • Dilip Choudhary finder

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE