Vulnerability Description
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths relative to the server's document root, this could expose sensitive files such as log files. This issue affects TYPO3 CMS versions 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30 and 14.0.0-14.3.2.
Related Weaknesses (CWE)
References
- https://github.com/TYPO3/typo3/commit/ad636b6183843b57c758a1e12174a75093ac93c3
- https://github.com/TYPO3/typo3/commit/caa6b444d7ab1bdd1eb76a68004c8be73d98e6ae
- https://typo3.org/security/advisory/typo3-core-sa-2026-013
FAQ
What is CVE-2026-49742?
CVE-2026-49742 is a documented vulnerability. Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths r...
How severe is CVE-2026-49742?
CVSS scoring is not yet available for CVE-2026-49742. Check NVD for updates.
Is there a patch for CVE-2026-49742?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.