ZeroHour

CVE-2026-85400

large

Privilege Escalation via Scheduled Commands in TYPO3 CMS 14.2-14.3.6

CVSS 4.0
7.5 high
EPSS
<1%p37
Published
()
Modified
AI analysis

TYPO3 CMS versions 14.2.0 through 14.3.6 fail to properly restrict scheduling of the configuration:read, configuration:set, and configuration:show commands, allowing backend administrators who lack system maintainer privileges to schedule them (incorrect privilege assignment / missing authorization, CWE-266/CWE-862). Exploitation requires an administrator-level backend user account, which can then create a scheduled task that runs these privileged configuration commands. Because these commands execute with system maintainer-level authority, the administrator can modify arbitrary system configuration — normally reserved for system maintainers — for example granting themselves system maintainer privileges or altering settings in a way that causes a denial of service. Any site running an affected TYPO3 CMS 14.2.x-14.3.x release is exposed, though the attacker must already hold a (non-maintainer) administrator backend account, so instances with few or trusted admins face lower risk. No public PoC is known, the issue is not in CISA KEV, and EPSS estimates only a ~0.4% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Upgrade TYPO3 CMS to a fixed release newer than 14.3.6 as indicated in the vendor's security advisory, since all 14.2.0-14.3.6 installations are affected. Until patched, restrict administrator-level backend accounts to trusted users, prevent non-maintainer admins from scheduling configuration:* commands, and audit existing scheduler records and recent system configuration changes for signs of tampering or self-granted maintainer privileges.

Affected
TYPO3 CMS14.2.0 through 14.3.6 (inclusive)
Estimated exposure
largetens of thousands of sites (roughly 10,000-50,000 of TYPO3's hundreds of thousands of active installations run the affected 14.2.0-14.3.6 range) — TYPO3 powers on the order of hundreds of thousands of active websites concentrated in Europe (government, education and enterprise), and the affected range spans the current 14.x major branch, so only the subset of sites running those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.

Weakness
CWE-266, CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.