PatchSiren cyber security CVE debrief
CVE-2026-85400 TYPO3 CVE debrief
CVE-2026-85400 allows backend administrators without system maintainer privileges to schedule configuration commands, enabling them to modify arbitrary system configurations and potentially gain system maintainer privileges or cause a denial of service. This issue affects TYPO3 CMS versions 14.2.0-14.3.6 and requires an administrator-level backend user account to exploit.
- Vendor
- TYPO3
- Product
- TYPO3 CMS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-08
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-09-08
- Advisory updated
- 2026-09-08
Who should care
Defenders responsible for TYPO3 CMS deployments, particularly those with backend administrator accounts, should assess exposure and verify system configurations to prevent potential modifications.
Why it matters
CVE-2026-85400 allows backend administrators to modify system configurations, potentially leading to privilege escalation or denial of service. Defenders should verify TYPO3 CMS versions, restrict backend access, and monitor configurations.
- Potential system configuration modifications require verification and monitoring.
- Possible escalation of privileges from backend administrator to system maintainer.
- Potential denial of service through configuration changes.
- Verification of TYPO3 CMS versions and backend administrator access restrictions is necessary.
Technical summary
CVE-2026-85400 is a vulnerability in TYPO3 CMS that allows backend administrators without system maintainer privileges to schedule configuration commands. This potentially leads to arbitrary system configuration modifications, system maintainer privilege escalation, or denial of service. The issue affects TYPO3 CMS versions 14.2.0-14.3.6 and requires an administrator-level backend user account to exploit. Defenders should prioritize verifying TYPO3 CMS versions and restricting backend administrator access to prevent potential configuration modifications.
Defensive priority
Defenders should prioritize verifying TYPO3 CMS versions and restricting backend administrator access to prevent potential configuration modifications.
Recommended defensive actions
- Verify TYPO3 CMS versions and ensure they are up-to-date
- Restrict backend administrator access to prevent potential configuration modifications
- Monitor system configurations for unauthorized changes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability. Source references offer insights into commits b8abe36978c63a0625aee70df078895216e7ee27 and e15da7ba0218532240578b471152f76c13cb4154, and advisory typo3-core-sa-2026-023. Defenders should verify TYPO3 CMS versions, restrict backend administrator access, and monitor configurations for unauthorized changes, noting evidence limits and potential exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-85400 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-85400
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-85400 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-85400
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/TYPO3/typo3/commit/b8abe36978c63a0625aee70df078895216e7ee27
f4fb688c-4412-4426-b4b8-421ecf27b14a
-
Source reference
Unverified legacy reference
URL: https://github.com/TYPO3/typo3/commit/e15da7ba0218532240578b471152f76c13cb4154
f4fb688c-4412-4426-b4b8-421ecf27b14a
-
Source reference
Unverified legacy reference
URL: https://news.typo3.com/security/advisory/typo3-core-sa-2026-023
f4fb688c-4412-4426-b4b8-421ecf27b14a
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.