---
cve: "CVE-2026-19418"
severity: "HIGH"
cvss: 7.3
epss: "21%"
vendor: "TYPO3"
kev: false
exploited: false
published: "2026-08-11 08:17:20"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T05:01:34+02:00"
---

# CVE-2026-19418

> 7.3 HIGH · 🧪 PoC

## Beschreibung

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory.

Whether a request originated from the backend or Install Tool itself was determined by comparing the referrer against the directory of the entry script, which since then is the site root. As a consequence, requests originating from any script running on one of the TYPO3 instance's own domains, such as a frontend page, were accepted by backend routes and Install Tool endpoints.

Attackers able to execute JavaScript on one of those domains, for instance by exploiting a cross-site scripting vulnerability, could invoke these endpoints via Fetch/XHR with the privileges of an authenticated victim's user session. This issue affects TYPO3 CMS versions 13.0.0-13.4.33 and 14.0.0-14.3.5.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |

## Patch verfügbar (OSV)

- 8273e2eb49cef644956175c8325b64d2bf064ab7 (Commit)
- dea0f4d4535620a43e02f2e1c0b6558a963b1b19 (Commit)

## Referenzen

- <https://typo3.org/security/advisory/typo3-core-sa-2026-021>
- <https://typo3.org/security/advisory/typo3-core-sa-2020-006>
- <https://github.com/TYPO3/typo3/commit/ae0abd329d52285fe6e92804c3608820ad45e872>
- <https://github.com/TYPO3/typo3/commit/a0e8ee06a40e959b9e7b06a4b1cb19d3a0d3dcf7>
- <https://github.com/TYPO3/typo3/commit/4a75e862c589c85d795d7c65dcdc835f8f413efc>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-19418) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
