CVE-2025-59020 - CVE House
Back to Database
Status published Medium CVE-2025-59020

TYPO3 CMS Allows Broken Access Control in Edit Document Controller

Vulnerability Description

By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set of fields. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59020

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Daniel Windloff
  • Benjamin Franzke

Affected Vendor

Affected Software

TYPO3 CMS
Vulnerable Versions:
10.0.0, 11.0.0, 12.0.0, 13.0.0, 14.0.0

Timeline

Official Publish: January 13th, 2026
Last Modified: January 13th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)