Skip to main navigation Skip to main content Skip to page footer

TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard

It has been discovered that TYPO3 CMS is susceptible to information disclosure.



Problem Description

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range.

Exploiting this vulnerability requires a low-privileged backend user account.

Solution

Update to TYPO3 versions 10.4.60 ELTS, 11.5.54 ELTS, 12.4.49 ELTS, 13.4.35 LTS, 14.3.7 LTS that fix the problem described.

Credits

Thanks to TYPO3 core & security team member Oliver Hader, Antariksha Akhilesh sharma, “kei”, David Gómez Bru, Khương Anh, Miro Hatachi, Phan Long, HDWSec, and El Mostafa Noujad for reporting this issue, and to TYPO3 core member Benjamin Kott for fixing it.

General Advice

Follow the recommendations that are given in the TYPO3 Security Guide.

General Note

All security-related code changes are tagged so you can easily look them up in our review system.