CVE-2026-49742 PUBLISHED

TYPO3 CMS - Broken Access Control in Media Module

Assigner: TYPO3
Reserved: 01.06.2026 Published: 09.06.2026 Updated: 09.06.2026

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor TYPO3
Product TYPO3 CMS
Versions Default: unaffected
  • affected from 11.0.0 to 11.5.51 (excl.)
  • affected from 12.0.0 to 12.4.46 (excl.)
  • affected from 13.0.0 to 13.4.31 (excl.)
  • affected from 14.0.0 to 14.3.3 (excl.)

Credits

  • Hyunseo Shin reporter
  • Torben Hansen remediation developer

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE
  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE