GHSA-q93m-25xv-94hh
TYPO3 CMS: Broken Access Control in Media Module
Quick fix
GHSA-q93m-25xv-94hh — typo3/cms-core: upgrade to the fixed version with the command below.
composer require typo3/cms-core:^10.4.57Details
### Problem Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission checks, which allowed users to gather information about records and files they were not authorized to view.
### Solution Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.
### Credits TYPO3 CMS thanks Vincent Yang for reporting this issue, and to TYPO3 security team member Elias Häußler for fixing it.
### Resources * [TYPO3-CORE-SA-2026-014](https://typo3.org/security/advisory/typo3-core-sa-2026-014)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 10.4.57composer require typo3/cms-core:^10.4.5711.0.0Fixed in: 11.5.51composer require typo3/cms-core:^11.5.5112.0.0Fixed in: 12.4.46composer require typo3/cms-core:^12.4.4613.0.0Fixed in: 13.4.31composer require typo3/cms-core:^13.4.3114.0.0Fixed in: 14.3.3composer require typo3/cms-core:^14.3.30Fixed in: 10.4.57composer require typo3/cms-backend:^10.4.5711.0.0Fixed in: 11.5.51composer require typo3/cms-backend:^11.5.5112.0.0Fixed in: 12.4.46composer require typo3/cms-backend:^12.4.4613.0.0Fixed in: 13.4.31composer require typo3/cms-backend:^13.4.3114.0.0Fixed in: 14.3.3composer require typo3/cms-backend:^14.3.3References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-q93m-25xv-94hh[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-47351[ADVISORY]
- https://github.com/TYPO3/typo3/commit/2740707563343d78184c0b7c6303a7484553d7f3[WEB]
- https://github.com/TYPO3/typo3/commit/932fbb9fcea25094e8bcc0f0ec5aab56b1d92451[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-47351.yaml[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2026-014[WEB]