Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. typo3/cms-core
  4. ›
  5. CVE-2026-49742

CVE-2026-49742: TYPO3 CMS has Broken Access Control in its Media Module

June 12, 2026

Problem

Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server’s document root, this could expose sensitive files such as log files.

Solution

Update to TYPO3 versions 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.

Credits

TYPO3 CMS thanks Hyunseo Shin for reporting this issue, and to TYPO3 security team member Torben Hansen for fixing it.

Resources

  • TYPO3-CORE-SA-2026-013

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-49742.yaml
  • github.com/TYPO3/typo3/commit/ad636b6183843b57c758a1e12174a75093ac93c3
  • github.com/TYPO3/typo3/commit/caa6b444d7ab1bdd1eb76a68004c8be73d98e6ae
  • github.com/TYPO3/typo3/security/advisories/GHSA-chm7-4vch-h8vr
  • github.com/advisories/GHSA-chm7-4vch-h8vr
  • nvd.nist.gov/vuln/detail/CVE-2026-49742
  • typo3.org/security/advisory/typo3-core-sa-2026-013

Code Behaviors & Features

Detect and mitigate CVE-2026-49742 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 11.0.0 before 11.5.51, all versions starting from 12.0.0 before 12.4.46, all versions starting from 13.0.0 before 13.4.31, all versions starting from 14.0.0 before 14.3.3

Fixed versions

  • 11.5.51
  • 12.4.46
  • 13.4.31
  • 14.3.3

Solution

Upgrade to versions 11.5.51, 12.4.46, 13.4.31, 14.3.3 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

packagist/typo3/cms-core/CVE-2026-49742.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:24:33 +0000.