CVE-2026-11607

Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, which were processed without denying the incorrect file extension. Maliciously crafted form definition files can be used to execute arbitrary SQL statements, allowing attackers to escalate privileges by creating administrative backend user accounts. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-09 11:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-11607

Mitre link : CVE-2026-11607

CVE.ORG link : CVE-2026-11607


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization