CVE-2026-85400
largePrivilege Escalation via Scheduled Commands in TYPO3 CMS 14.2-14.3.6
TYPO3 CMS versions 14.2.0 through 14.3.6 fail to properly restrict scheduling of the configuration:read, configuration:set, and configuration:show commands, allowing backend administrators who lack system maintainer privileges to schedule them (incorrect privilege assignment / missing authorization, CWE-266/CWE-862). Exploitation requires an administrator-level backend user account, which can then create a scheduled task that runs these privileged configuration commands. Because these commands execute with system maintainer-level authority, the administrator can modify arbitrary system configuration — normally reserved for system maintainers — for example granting themselves system maintainer privileges or altering settings in a way that causes a denial of service. Any site running an affected TYPO3 CMS 14.2.x-14.3.x release is exposed, though the attacker must already hold a (non-maintainer) administrator backend account, so instances with few or trusted admins face lower risk. No public PoC is known, the issue is not in CISA KEV, and EPSS estimates only a ~0.4% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Upgrade TYPO3 CMS to a fixed release newer than 14.3.6 as indicated in the vendor's security advisory, since all 14.2.0-14.3.6 installations are affected. Until patched, restrict administrator-level backend accounts to trusted users, prevent non-maintainer admins from scheduling configuration:* commands, and audit existing scheduler records and recent system configuration changes for signs of tampering or self-granted maintainer privileges.
| TYPO3 CMS | 14.2.0 through 14.3.6 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system configuration, which is normally limited to system maintainers. As a consequence, this allowed them, for example, to gain system maintainer privileges or cause a denial of service. Exploiting this vulnerability requires an administrator-level backend user account. This issue affects TYPO3 CMS versions 14.2.0-14.3.6.
- Weakness
- CWE-266, CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.