Referrer Enforcement Bypass in TYPO3 CMS
CVE-2026-19418
What is CVE-2026-19418?
A bypass vulnerability has been identified in TYPO3 CMS affecting versions 13.0.0 to 13.4.33 and 14.0.0 to 14.3.5. The issue arises from the referrer enforcement mechanism, which became ineffective starting from TYPO3 v13.0. The CMS began serving backend and Install Tool applications from the site's main entry script instead of a dedicated directory. This change means that the system can mistakenly accept requests from any script on the same domain, potentially enabling attackers to exploit weaknesses such as cross-site scripting (XSS) to access backend routes and Install Tool endpoints. This vulnerability could lead to significant security breaches if left unaddressed, making it crucial for users on affected versions to apply recommended patches immediately and review their security practices.
Affected Version(s)
TYPO3 CMS 13.0.0 < 13.4.34
TYPO3 CMS 14.0.0 < 14.3.6
TYPO3 CMS 13.0.0 < 13.4.34
