PatchSiren cyber security CVE debrief
CVE-2026-19418 TYPO3 CVE debrief
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 became ineffective in TYPO3 v13.0, allowing requests from any script running on a TYPO3 instance's own domains to be accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impact. The CVE record was published on 2026-08-11T08:17:20.533Z and has not been modified since then. The NVD entry is currently Deferred. TYPO3 CMS administrators and users, security teams, and vulnerability management professionals should review and update TYPO3 CMS to version 13.4.34 or 14.3.6, or later. Additional security measures should be implemented to restrict access to backend routes and Install Tool endpoints. Monitoring for suspicious activity on TYPO3 instance domains is also recommended.
- Vendor
- TYPO3
- Product
- TYPO3 CMS
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-26
Who should care
TYPO3 CMS administrators and users, security teams, and vulnerability management professionals should review and update TYPO3 CMS to version 13.4.34 or 14.3.6, or later. Additional security measures should be implemented to restrict access to backend routes and Install Tool endpoints. Monitoring for suspicious activity on TYPO3 instance domains is also recommended. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5, and may impact organizations using these versions in production environments or under active exploitation by threat actors with JavaScript execution capabilities on affected domains. Security teams should prioritize patching and implement compensating controls for exposed systems while remediation is scheduled and verified. Vulnerability management professionals should track exceptions, retest remediated assets, and close the item only after evidence is documented. IT operators managing TYPO3 instances should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also review compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory management and source tracking are crucial for ensuring comprehensive mitigation and response to this vulnerability. Rolling back change windows and implementing additional security measures can help mitigate potential risks associated with this vulnerability. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts on TYPO3 instance domains. By taking these steps, organizations can reduce the risk of exploitation and protect their TYPO3 CMS deployments from potential attacks. Security teams and vulnerability management professionals should work together to ensure that all necessary measures are taken to mitigate this vulnerability effectively. This may involve coordinating with IT operators to implement patches, compensating controls, and monitoring solutions. Effective communication and collaboration are essential for successful mitigation.
Technical summary
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 became ineffective in TYPO3 v13.0. Requests originating from any script running on one of the TYPO3 instance's own domains were accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session.
Defensive priority
Authenticated attackers with JavaScript execution capabilities on a TYPO3 instance's domain could exploit this vulnerability to invoke backend routes and Install Tool endpoints with victim session privileges.
Recommended defensive actions
- Review and update TYPO3 CMS to version 13.4.34 or 14.3.6, or later
- Implement additional security measures to restrict access to backend routes and Install Tool endpoints
- Monitor for suspicious activity on TYPO3 instance domains
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 became ineffective in TYPO3 v13.0. Requests originating from any script running on one of the TYPO3 instance's own domains were accepted by backend routes and Install Tool endpoints. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19418 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19418
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19418 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19418
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/TYPO3/typo3/commit/4a75e862c589c85d795d7c65dcdc835f8f413efc
f4fb688c-4412-4426-b4b8-421ecf27b14a
-
Source reference
Unverified legacy reference
URL: https://github.com/TYPO3/typo3/commit/a0e8ee06a40e959b9e7b06a4b1cb19d3a0d3dcf7
f4fb688c-4412-4426-b4b8-421ecf27b14a
-
Source reference
Unverified legacy reference
URL: https://github.com/TYPO3/typo3/commit/ae0abd329d52285fe6e92804c3608820ad45e872
f4fb688c-4412-4426-b4b8-421ecf27b14a
-
Source reference
Unverified legacy reference
URL: https://typo3.org/security/advisory/typo3-core-sa-2020-006
f4fb688c-4412-4426-b4b8-421ecf27b14a
-
Source reference
Unverified legacy reference
URL: https://typo3.org/security/advisory/typo3-core-sa-2026-021
f4fb688c-4412-4426-b4b8-421ecf27b14a
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.