CVE-2026-19418
Last modified
CVE-2026-19418 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints. Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| TYPO3 | TYPO3 CMS | >= 13.0.0, < 13.4.34; >= 14.0.0, < 14.3.6 |
| TYPO3 | TYPO3 CMS | >= 14.0.0, < 14.3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19418?
How severe is CVE-2026-19418?
How do I fix CVE-2026-19418?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1941The WP Event Aggregator plugin for WordPress is vulnerable t…6.4
- CVE-2026-19410An Incorrect Authorization vulnerability in GitHub Trigger C…9.4
- CVE-2026-19411A NULL pointer vulnerability has been found in the the shim …3.9
- CVE-2026-19412This vulnerability exists in the CP Plus CP-XR-DE21-S Router…8.7
- CVE-2026-19416The KiviCare WordPress plugin before 4.5.4 does not verify …4.3
- CVE-2026-19417The KiviCare WordPress plugin before 4.5.4 does not verify …6.5
- CVE-2026-1942The Blog2Social: Social Media Auto Post & Scheduler plugin f…6.5
- CVE-2026-19423The Ultimate Member WordPress plugin before 2.13.0 does not…8.1
- CVE-2026-19424Chiline Cloud developed by Inventec Appliances has a Insecur…7.5
- CVE-2026-19425Travel Agency Management System developed by Win Men Interma…9.8
- CVE-2026-19426POS System developed by FitSoft has a Missing Authentication…8.2
- CVE-2026-19429Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2026-19418?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
