Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qcmw-6rm2-5x78 | TYPO3 CMS has Broken Access Control in its DataHandler |
Tue, 09 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backend users were able to move records to a different page without having edit permissions on the source page. This issue affects TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3. | |
| Title | TYPO3 CMS - Broken Access Control in DataHandler | |
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-06-09T13:50:29.584Z
Reserved: 2026-05-19T12:49:25.966Z
Link: CVE-2026-47350
Updated: 2026-06-09T13:50:25.316Z
Status : Deferred
Published: 2026-06-09T11:16:52.860
Modified: 2026-06-09T13:46:50.540
Link: CVE-2026-47350
No data.
OpenCVE Enrichment
Updated: 2026-06-09T20:15:06Z
Github GHSA