CVE-2026-6553 is a password storage vulnerability affecting TYPO3 CMS version 14.2.0, wherein changing backend user passwords through the user settings module results in cleartext password storage in the uc and user_settings database fields. This represents a critical flaw in credential management that could expose sensitive authentication data. The vulnerability carries a FAUCET Risk Score of 47.0/100, indicating moderate concern. While specific CVSS vector details are unavailable, the core issue involves improper password handling at the application level, likely requiring administrative access to the backend user settings module to trigger the vulnerability, which may limit initial attack surface. Current exploitation activity appears minimal, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is classified as inactive on threat intelligence platforms. The exceptionally low EPSS score of 0.00029 suggests negligible real-world exploitation likelihood at this time. However, the vulnerability warrants prompt patching given its direct impact on credential confidentiality and the ease with which an authenticated attacker could trigger password exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 14.2.0, < 14.3.0CPE match | cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:* | ||
14.2.0CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:14.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.