Description
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they were not authorized to modify. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3.
Problem types
Product status
Any version before 10.4.57
11.0.0 (semver) before 11.5.51
12.0.0 (semver) before 12.4.46
13.0.0 (semver) before 13.4.31
14.0.0 (semver) before 14.3.3
Credits
Hyunseo Shin
Elias Häußler
References
typo3.org/security/advisory/typo3-core-sa-2026-011
github.com/...ommit/9f17a307cf774d63ab8291fc97c6b55653b4265a (Git commit of main branch)
github.com/...ommit/92f08d8944f1aeccf506fcd323c260448c64d7c8 (Git commit of 13.4 branch)