TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard

It has been discovered that TYPO3 CMS is susceptible to information disclosure.
- Component Type: TYPO3 CMS
- Subcomponent: Localization (ext:backend)
- Release Date: September 8, 2026
- Vulnerability Type: Information Disclosure
- Affected Versions: 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34, 14.0.0-14.3.6
- Severity: Medium
- Suggested CVSS: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- References: CVE-2026-77132, CWE-862, CWE-200
Problem Description
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range.
Exploiting this vulnerability requires a low-privileged backend user account.
Solution
Update to TYPO3 versions 10.4.60 ELTS, 11.5.54 ELTS, 12.4.49 ELTS, 13.4.35 LTS, 14.3.7 LTS that fix the problem described.
Credits
Thanks to TYPO3 core & security team member Oliver Hader, Antariksha Akhilesh sharma, “kei”, David Gómez Bru, Khương Anh, Miro Hatachi, Phan Long, HDWSec, and El Mostafa Noujad for reporting this issue, and to TYPO3 core member Benjamin Kott for fixing it.
General Advice
Follow the recommendations that are given in the TYPO3 Security Guide.
General Note
All security-related code changes are tagged so you can easily look them up in our review system.
