CVE-2026-49740 | TYPO3 CMS up to 14.3.2 Storage Backend or deserialization (WID-SEC-2026-1835)
A vulnerability was found in TYPO3 CMS up to 10.4.56/11.5.50/12.4.45/13.4.30/14.3.2 and classified as problematic. This affects the function or of the component Storage Backend. The manipulation results in deserialization.
This vulnerability is reported as CVE-2026-49740. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.