THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-68jx-f42c-7599 (high) — TYPO3 CMS - Broken Access Control in Backend and Install Tool

[GHSA] GHSA-68jx-f42c-7599 (high) — TYPO3 CMS - Broken Access Control in Backend and Install Tool

highgithub_advisoriesPublished 2026-09-01

GHSA-68jx-f42c-7599 Severity: high CVE: CVE-2026-19418

TYPO3 CMS - Broken Access Control in Backend and Install Tool

### Problem The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-68jx-f42c-7599