Intel

AIKIDO-2026-885460

typo3/cms-backend is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-77132 Published Today

53

Medium Risk

This Affects:

PHPtypo3/cms-backend
10.0.0 - 13.4.34
Fixed in 13.4.35
14.0.0 - 14.3.6
Fixed in 14.3.7
Are you affected? Scan for Free

TL;DR

Several AJAX routes used by the backend localization wizard skip authorization checks before returning record and content-element metadata. An authenticated low-privileged backend user can therefore read information about records outside their permitted range. The fix enforces authorization on those localization wizard AJAX routes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and low-privileged backend users can access the localization wizard AJAX routes.

Background info

typo3/cms-backend is vulnerable to Missing Authorization in versions 10.0.0 - 13.4.34 and 14.0.0 - 14.3.6.

How to fix this

Upgrade the typo3/cms-backend library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform