Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://backdropcms.org/security/backdrop-sa-core-2026-006 |
|
History
Fri, 09 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient Protection of Configuration Exports in Backdrop CMS |
Fri, 09 Oct 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. | |
| First Time appeared |
Backdropcms
Backdropcms backdrop |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Backdropcms
Backdropcms backdrop |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-09T05:18:26.529Z
Reserved: 2026-10-09T05:18:25.745Z
Link: CVE-2026-107914
No data.
Status : Received
Published: 2026-10-09T06:17:12.777
Modified: 2026-10-09T06:17:12.777
Link: CVE-2026-107914
No data.
OpenCVE Enrichment
Updated: 2026-10-09T06:30:17Z
Weaknesses