Referrer Enforcement Bypass in TYPO3 CMS
CVE-2026-19418

7.3HIGH

Key Information:

Vendor

Typo3

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-19418?

A bypass vulnerability has been identified in TYPO3 CMS affecting versions 13.0.0 to 13.4.33 and 14.0.0 to 14.3.5. The issue arises from the referrer enforcement mechanism, which became ineffective starting from TYPO3 v13.0. The CMS began serving backend and Install Tool applications from the site's main entry script instead of a dedicated directory. This change means that the system can mistakenly accept requests from any script on the same domain, potentially enabling attackers to exploit weaknesses such as cross-site scripting (XSS) to access backend routes and Install Tool endpoints. This vulnerability could lead to significant security breaches if left unaddressed, making it crucial for users on affected versions to apply recommended patches immediately and review their security practices.

Affected Version(s)

TYPO3 CMS 13.0.0 < 13.4.34

TYPO3 CMS 14.0.0 < 14.3.6

TYPO3 CMS 13.0.0 < 13.4.34

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hổ Cao Từ
Benjamin Franzke
.