THREAT OPS › Threat News › [GHSA] GHSA-68jx-f42c-7599 (high) — TYPO3 CMS - Broken Access Control in Backend and Install Tool
[GHSA] GHSA-68jx-f42c-7599 (high) — TYPO3 CMS - Broken Access Control in Backend and Install Tool
GHSA-68jx-f42c-7599 Severity: high CVE: CVE-2026-19418
TYPO3 CMS - Broken Access Control in Backend and Install Tool
### Problem The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-19418cve
- CVE-2020-11069cve
- https://news.typo3.com/security/advisory/typo3-core-sa-2020-006url
- https://www.cve.org/CVERecord?id=CVE-2020-11069url
Original source: https://github.com/advisories/GHSA-68jx-f42c-7599