Security Advisory

CVE-2026-6553

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-21 10:04:02
Last updated 2026-04-21 13:20:23
Assigner TYPO3
CVSS score 7.3
State PUBLISHED

Description

Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.