Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-0895

20
FAUCET Score

CVE-2026-0895 describes an Insecure Deserialization vulnerability affecting a TYPO3 extension that overwrites a core fix. This allows the vulnerability, originally addressed in TYPO3-CORE-SA-2026-004, to persist even in patched TYPO3 core versions. With a CVSS score of 5.2 (Medium), the vulnerability requires local access and low privileges, but can lead to high impact on confidentiality, integrity, and availability. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
TYPO3Extension "Mailqueue"
>= 0, < 0.4.3, >= 0.5.0, < 0.5.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

5.2MEDIUM

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.12%
Probability of exploitation in next 30 days
EPSS Percentile
2.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0012 is in the 15th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: cpsit/typo3-mailqueueFixed in: 0.4.3
composerpatch availablevia ghsa
Product: cpsit/typo3-mailqueueFixed in: 0.5.1

Vendor Advisories (1)

composerGHSA-ggff-9mj3-7246medium

mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport

Jan 21, 2026

References

github.com / CPS-IT/mailqueue/commit/12a0a35027bb5609917790a94e43bbf117abf733
github.com / CPS-IT/mailqueue/commit/fd09aa4e1a751551bae4b228bee814e22f2048db
typo3.org / security/advisory/typo3-ext-sa-2026-001