CVE-2025-59022

HIGH EPSS 29.8%
Published Jan 13, 20265mo ago · Modified Jun 17, 20261w ago
7.1 CVSS 4.0
High
Find Similar
Published Jan 13, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago

Description

Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering the website unavailable. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.

CVSS Details

Base Score
7.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
29.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-862 Missing Authorization Authorization

Affected Products 5

VendorProductVersionRange
typo3typo3*≥10.0.0  –  <10.4.55
typo3typo3*≥11.0.0  –  <11.5.49
typo3typo3*≥12.0.0  –  <12.4.41
typo3typo3*≥13.0.0  –  <13.4.23
typo3typo3*≥14.0.0  –  <14.0.2

References 4

  • github.com https://github.com/TYPO3/typo3/commit/336d6f165458a0ce32d8330999ab9ab6a5983d20
    Patch
  • github.com https://github.com/TYPO3/typo3/commit/a6604db66499710f72ae6e7006beb14ad0913aae
    Patch
  • github.com https://github.com/TYPO3/typo3/commit/efb9528f9882ac924c40598ebd8508479e9950a3
    Patch
  • typo3.org https://typo3.org/security/advisory/typo3-core-sa-2026-003
    Vendor Advisory

Remediation

  • github.com https://github.com/TYPO3/typo3/commit/336d6f165458a0ce32d8330999ab9ab6a5983d20
    Patch
  • github.com https://github.com/TYPO3/typo3/commit/a6604db66499710f72ae6e7006beb14ad0913aae
    Patch
  • github.com https://github.com/TYPO3/typo3/commit/efb9528f9882ac924c40598ebd8508479e9950a3
    Patch