CVE-2026-0859
TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server.
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server. This issue affects TYPO3 CMS versions 10.0.0-10.4.54, 11.0.0-11.5.48, 12.0.0-12.4.40, 13.0.0-13.4.22 and 14.0.0-14.0.1.
- CVSS 4.0
- 5.2 MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- typo3/typo3
- Source
- f4fb688c-4412-4426-b4b8-421ecf27b14a
References
- https://github.com/TYPO3/typo3/commit/3225d705080a1bde57a66689621c947da5a4782fPatch
- https://github.com/TYPO3/typo3/commit/722bf71c118b0a8e4f2c2494854437d846799a13Patch
- https://github.com/TYPO3/typo3/commit/e0f0ceee480c203fbb60b87454f5f193e541d27fPatch
- https://typo3.org/security/advisory/typo3-core-sa-2026-004Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.