CVE-2026-49738 PUBLISHED

TYPO3 CMS - Broken Access Control in File Abstraction Layer

Assigner: TYPO3
Reserved: 01.06.2026 Published: 09.06.2026 Updated: 09.06.2026

The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requiring a directory separator boundary, causing a path like /var/www/html-other/secret.yaml to be incorrectly accepted as valid when the project root was /var/www/html. Administrator users with access to the File Abstraction Layer were able to create new file storage definitions pointing to directories outside the project root, bypassing this path check. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.1

Product Status

Vendor TYPO3
Product TYPO3 CMS
Versions Default: unaffected
  • affected from 0 to 10.4.57 (excl.)
  • affected from 11.0.0 to 11.5.51 (excl.)
  • affected from 12.0.0 to 12.4.46 (excl.)
  • affected from 13.0.0 to 13.4.31 (excl.)
  • affected from 14.0.0 to 14.3.3 (excl.)

Credits

  • Wolfgang Klinger reporter
  • Oliver Hader remediation developer

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE