GHSA-jh32-v29g-68pq
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
Quick fix
GHSA-jh32-v29g-68pq — typo3/cms-core: upgrade to the fixed version with the command below.
composer require typo3/cms-core:^14.3.3Details
### Problem Backend users with write access to the `form_definition` database table were able to directly create, update, or delete form definition records via `DataHandler`, bypassing the Form Framework's persistence validation and permission checks. This allowed injecting arbitrary form configurations, re-enabling attack vectors originally addressed in [TYPO3-CORE-SA-2018-003](https://typo3.org/security/advisory/typo3-core-sa-2018-003), including SQL injection and privilege escalation.
### Solution Update to TYPO3 version 14.3.3 LTS that fixes the problem described.
### Credits TYPO3 CMS thanks Selçuk Güney for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it.
### Resources * [TYPO3-CORE-SA-2026-017](https://typo3.org/security/advisory/typo3-core-sa-2026-017)
Are you affected?
Enter the version of the package you're using.
Affected packages
14.0.0Fixed in: 14.3.3composer require typo3/cms-core:^14.3.314.0.0Fixed in: 14.3.3composer require typo3/cms-form:^14.3.3References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-jh32-v29g-68pq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-49741[ADVISORY]
- https://github.com/TYPO3/typo3/commit/c90493c13b633f328cf2c066182c90a1655ff0fc[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-49741.yaml[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2018-003[WEB]
- https://typo3.org/security/advisory/typo3-core-sa-2026-017[WEB]