CVE 8.7 HIGH

TYPO3 CMS – Privilege Escalation & SQL Injection in Form Framework_CVE-2026-49741

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Description

Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persistence validation and permission checks. This allowed injecting arbitrary form configurations, re-enabling attack vectors originally addressed in TYPO3-CORE-SA-2018-003, including SQL injection and privilege escalation. This issue affects TYPO3 CMS versions 14.0.0-14.3.3.

AI Analysis

Privilege escalation and SQL injection vulnerability in Form Framework

Basic Information

ID CVE-2026-49741
Source TYPO3
Published Jun 9, 2026 at 10:54

Affected Product

Vendor TYPO3
Product TYPO3 CMS
Version 14.0.0
Affected Versions TYPO3 TYPO3 CMS 14.0.0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor TYPO3
Product TYPO3 CMS
Version 14.0.0-14.3.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.