CVE-2026-6553Disclosure(typo3 / typo3)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-312

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • typo3

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-21); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
typo3

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-21: 3Mentions · 2026-04-24: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-21: 3Technical Details · 2026-04-24: 1Technical Details · 2026-04-28: 104-2104-2404-28
Signal classification1 categories
Disclosure
5100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-213
Disclosure3
2026-04-241
Disclosure1
2026-04-281
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6553 Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database tab… https://www.cve.org/CVERecord?id=CVE-2026-6553

    Post summary

    The text reports a new vulnerability (CVE‑2026‑6553) where updating backend passwords results in cleartext storage in the database, with no evidence of exploitation, patch, or false‑positive confirmation.

    0001056
    57.2K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-6553: CVE-2026-6553: Cleartext Password Exposure in TYPO3 CMS Backend User Settings CVE-2026-6553 is a high-severity sensitive data exposure vulnerability (CWE-312) in TYPO3 CMS version 14.2.0. The vulnerability allows plaintext backend user ... https://cvereports.com/reports/CVE-2026-6553

    Post summary

    The report announces a high‑severity plaintext password exposure in TYPO3 CMS version 14.2.0, offering basic technical details but lacking PoC, exploit, activeness, or patch information.

    0000022
    36 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 TYPO3, Cleartext Storage of Sensitive Information, #CVE-2026-6553 (High) https://dailycve.com/typo3-cleartext-storage-of-sensitive-information-cve-2026-6553-high/

    Post summary

    The post announces the disclosure of a new TYPO3 vulnerability (CVE-2026-6553) involving cleartext storage of sensitive data, providing no PoC, exploit code, or patch details.

    0000033
    183 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『The cleartext data was only persisted if users changed their credentials in the backend user settings module when the TYPO3 14.2.0 release was used (not in any other version).』 CVE-2026-6553 TYPO3 CMS Stores Cleartext Password in User Settings Module https://github.com/TYPO3/typo3/security/advisories/GHSA-xvv6-p4wf-mvx7

    Post summary

    The advisory reveals that TYPO3 14.2.0 stores cleartext passwords only when users change credentials in the backend, a security misconfiguration, but provides no evidence of exploitation or a PoC.

    00000477
    6.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6553 Cleartext Password Storage in TYPO3 CMS 14.2.0 Backend Use... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6553 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-6553, a clear‑text password storage vulnerability in TYPO3 CMS 14.2.0, but provides no PoC, exploitation details, or patch information.

    0000031
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptypo3typo314.2.0--

Explore more