Vulnerability Description
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2.
Related Weaknesses (CWE)
References
- https://github.com/TYPO3/typo3/commit/2740707563343d78184c0b7c6303a7484553d7f3
- https://github.com/TYPO3/typo3/commit/932fbb9fcea25094e8bcc0f0ec5aab56b1d92451
- https://typo3.org/security/advisory/typo3-core-sa-2026-014
FAQ
What is CVE-2026-47351?
CVE-2026-47351 is a documented vulnerability. Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they wer...
How severe is CVE-2026-47351?
CVSS scoring is not yet available for CVE-2026-47351. Check NVD for updates.
Is there a patch for CVE-2026-47351?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.