Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6553

26
FAUCET Score

CVE-2026-6553 is a password storage vulnerability affecting TYPO3 CMS version 14.2.0, wherein changing backend user passwords through the user settings module results in cleartext password storage in the uc and user_settings database fields. This represents a critical flaw in credential management that could expose sensitive authentication data. The vulnerability carries a FAUCET Risk Score of 47.0/100, indicating moderate concern. While specific CVSS vector details are unavailable, the core issue involves improper password handling at the application level, likely requiring administrative access to the backend user settings module to trigger the vulnerability, which may limit initial attack surface. Current exploitation activity appears minimal, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is classified as inactive on threat intelligence platforms. The exceptionally low EPSS score of 0.00029 suggests negligible real-world exploitation likelihood at this time. However, the vulnerability warrants prompt patching given its direct impact on credential confidentiality and the ease with which an authenticated attacker could trigger password exposure.

Impacted Technologies

VendorProductVersion(s)CPE
>= 14.2.0, < 14.3.0CPE match
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
14.2.0CPE matchmatch criteria
cpe:2.3:a:typo3:typo3:14.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.3HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 0th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: typo3/cms-backendFixed in: 14.3.0
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-xvv6-p4wf-mvx7high

TYPO3 CMS Stores Cleartext Password in User Settings Module

Apr 24, 2026

References

github.com / TYPO3/typo3/commit/9a6e913f70767f63b322ae3e2d2f4e302624c291
Patch
typo3.org / security/advisory/typo3-core-sa-2026-005
Vendor Advisory