CVE-2026-104476
Received Received - Intake

Information Disclosure in Backdrop CMS Prior to 1.35.1

Vulnerability report for CVE-2026-104476, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulnCheck

Description

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
backdrop cms to 1.35.1 (exc)
backdrop cms to 1.34.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Backdrop CMS before version 1.35.1 has an information disclosure vulnerability where unauthenticated attackers can download configuration export archives left on the server. These archives contain full site configuration details, including sensitive settings, after being generated by users with export permissions.

Detection Guidance

Check for exposed configuration export archives (config.tar.gz) in your Backdrop CMS installation directory, particularly in temporary or downloadable paths. Search for files matching the pattern config*.tar.gz in web-accessible directories like files/config_* or tmp/. Use commands like find /path/to/backdrop -name 'config*.tar.gz' to locate potential archives.

Impact Analysis

Attackers could obtain sensitive site configuration, including critical system settings, potentially leading to further attacks like unauthorized access, data breaches, or system compromise. The vulnerability allows full configuration exposure without authentication.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations due to unauthorized access to sensitive configuration data. Exposure of personal or health information in configurations may violate privacy and security requirements.

Mitigation Strategies

Upgrade Backdrop CMS to version 1.35.1 or later immediately. Verify the patch by checking for the shutdown function in config.admin.inc and permission checks in config.module. Remove any existing config.tar.gz files from your server to prevent further exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104476. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart