What is CVE-2026-19418?
The referrer enforcement introduced to prevent security issues (originally with CVE-2020-11069) became ineffective in TYPO3 CMS v13.0. This occurred because the backend and Install Tool applications are now served from the site's main entry script instead of the dedicated typo3/ directory. Users should apply the latest security update.
Azərbaycanca: TYPO3 CMS-in 13.0 versiyasında əvvəlki təhlükəsizlik düzəlişi (CVE-2020-11069) ilə tətbiq olunan referrer enforcement mexanizmi sıradan çıxıb. Bu, backend və Install Tool tətbiqlərinin artıq əsas giriş skriptindən xidmət göstərməsi səbəbindən baş verir. TYPO3 istifadəçiləri yeniləməni tətbiq etməlidir.
FAQ2
In which version of TYPO3 CMS did the referrer enforcement mechanism become ineffective?
In TYPO3 CMS version 13.0.
Why did the referrer enforcement mechanism become ineffective in TYPO3 CMS 13.0?
Because the backend and Install Tool applications are now served from the site's main entry script instead of the dedicated typo3/ directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.