Compound WireTHE STANDUP2 September 2026
TYPO3
ADMIN BACKEND, NO LOGIN NEEDED
TYPO3 bug lets attackers into admin backend, no login needed
CVE-2026-19418, HIGH, in typo3/cms-backend: the referrer enforcement TYPO3 shipped in 2020 for CVE-2020-11069 became ineffective in v13.0, when the backend and Install Tool started being served from the site's main entry script instead of the dedicated typo3/ directory. The check identified backend requests by comparing the referrer, so moving the entry point is what defeated it.