cvesecurityvulnerability
CVE-2026-19418: TYPO3 CMS Backend Access Control Bypass via Referrer Enforcement Failure
TYPO3 CMS 13.0.0-13.4.33 and 14.0.0-14.3.5 ship a broken referrer check that became inert when v13 moved the backend entry point to the site root. Any same-domain JavaScript can invoke backend and Install Tool endpoints with an authenticated session. Fixed in 13.4.34 and 14.3.6.