CVE-2026-85400
Deferred Deferred - Pending Action

Backend Admin Privilege Escalation in TYPO3 CMS

Vulnerability report for CVE-2026-85400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: TYPO3

Description

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account.Β This issue affects TYPO3 CMS versions 14.2.0-14.3.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
typo3 typo3_cms From 14.2.0 (inc) to 14.3.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows backend administrators without system maintainer privileges to schedule configuration commands like read, set, or show. This lets them modify system configurations that should be restricted to maintainers, potentially leading to privilege escalation or denial of service.

Impact Analysis

If you are a backend administrator in a vulnerable TYPO3 CMS version (14.2.0-14.3.6), an attacker with your credentials could exploit this to gain higher privileges or disrupt services. This requires an administrator account but could lead to full system compromise.

Compliance Impact

This vulnerability could lead to unauthorized system changes, potentially violating data integrity and access control requirements in GDPR or HIPAA. Unauthorized privilege escalation may also result in non-compliance with security and audit standards.

Mitigation Strategies

Update TYPO3 CMS to version 14.3.6 or later to address the vulnerability. Ensure only system maintainers have access to configuration commands. Review administrator accounts for unauthorized privilege escalations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85400. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart