CVE-2026-0859 describes a deserialization flaw in TYPO3's mail-file spool, affecting versions 10.0.0 through 14.0.1. This vulnerability allows a local attacker with write access to the spool directory to craft a malicious file, leading to arbitrary PHP code execution on the web server when the mailer:spool:send command is executed. Rated 7.8 HIGH on CVSS, the attack requires local access and low privileges, but can result in high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.4.55CPE match | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.5.49CPE match | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.4.41CPE match | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 13.0.0, < 13.4.23CPE match | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
>= 14.0.0, < 14.0.2CPE match | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.