PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47350 TYPO3 CVE debrief

A vulnerability in TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3 allows backend users to move records to a different page without having edit permissions on the source page. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity.

Vendor
TYPO3
Product
TYPO3 CMS
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-09
Advisory published
2026-06-09
Advisory updated
2026-06-09

Who should care

Users of TYPO3 CMS versions 13.0.0-13.4.31 and 14.0.0-14.3.3 should be aware of this vulnerability and take steps to mitigate it.

Technical summary

The vulnerability is caused by a lack of proper permission checks when moving records to a different page. This allows backend users to perform actions they should not have permission for.

Defensive priority

MEDIUM

Recommended defensive actions

  • Update TYPO3 CMS to version 13.4.32 or later, or 14.3.4 or later.
  • Review and adjust permissions for backend users to prevent unauthorized actions.

Evidence notes

The CVE record and NVD detail pages provide additional information about this vulnerability.

Official resources

CVE-2026-47350 was published on 2026-06-09T11:16:52.860Z and modified on 2026-06-09T13:46:50.540Z.