Information Disclosure Vulnerability in Backdrop CMS
CVE-2026-104476

8.2HIGH

Key Information:

Vendor

Backdrop

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104476?

Backdrop CMS versions prior to 1.35.1 are susceptible to an information disclosure vulnerability. This flaw enables unauthenticated attackers to access sensitive configuration export archives that may have been left on the server post-transfer. These archives contain critical site configuration details and settings, potentially exposing sensitive information that can be exploited for further attacks or unauthorized access. Users and administrators are urged to update to the latest version to ensure complete protection against this threat.

Affected Version(s)

backdrop 0 < 1.35.1

backdrop 1.35.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dilip Choudhary
.