Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view. This issue affects TYPO3 CMS versions 10.4.0-13.4.30 and 14.0.0-14.3.2. | |
| Title | TYPO3 CMS - Broken Access Control in Clipboard | |
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Weaknesses | CWE-200 CWE-862 |
|
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-06-09T10:52:38.150Z
Reserved: 2026-05-19T12:49:25.966Z
Link: CVE-2026-47351
No data.
Status : Received
Published: 2026-06-09T11:16:52.993
Modified: 2026-06-09T11:16:52.993
Link: CVE-2026-47351
No data.
OpenCVE Enrichment
Updated: 2026-06-09T12:30:04Z