GHSA-3v8v-4wg6-r7qh
TYPO3 CMS: Destructive Actions on File Mount Folders
Quick fix
GHSA-3v8v-4wg6-r7qh — typo3/cms-core: upgrade to the fixed version with the command below.
composer require typo3/cms-core:^10.4.57Details
### Problem Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions.
### Solution Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
### Credits TYPO3 CMS thanks Arne Uplegger for reporting this issue, and TYPO3 security team member Elias Häußler for fixing it.
### Resources * [TYPO3-CORE-SA-2026-007](https://typo3.org/security/advisory/typo3-core-sa-2026-007)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 10.4.57composer require typo3/cms-core:^10.4.5711.0.0Fixed in: 11.5.51composer require typo3/cms-core:^11.5.5112.0.0Fixed in: 12.4.46composer require typo3/cms-core:^12.4.4613.0.0Fixed in: 13.4.31composer require typo3/cms-core:^13.4.3114.0.0Fixed in: 14.3.3composer require typo3/cms-core:^14.3.3References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-3v8v-4wg6-r7qh[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-47343[ADVISORY]
- https://github.com/TYPO3/typo3/commit/504e72470ff72aaf5d2256878bf473747f389798[WEB]
- https://github.com/TYPO3/typo3/commit/ac4125aef8b9b94528a7f74db2444db57b05a87b[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47343.yaml[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2026-007[WEB]