By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set of fields. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 13 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set of fields. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1. | |
| Title | TYPO3 CMS Allows Broken Access Control in Edit Document Controller | |
| First Time appeared |
Typo3
Typo3 typo3 |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Typo3
Typo3 typo3 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published: 2026-01-13T11:53:02.274Z
Updated: 2026-01-13T16:43:00.776Z
Reserved: 2025-09-07T19:01:20.436Z
Link: CVE-2025-59020
Updated: 2026-01-13T16:42:57.405Z
Status : Analyzed
Published: 2026-01-13T12:15:49.913
Modified: 2026-01-14T19:15:16.077
Link: CVE-2025-59020
No data.