No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 09 Oct 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient Protection of Configuration Exports in Backdrop CMS |
Fri, 09 Oct 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-497 |
Fri, 09 Oct 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. | Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. NOTE: CVE-2026-107914 refers to the vulnerability in which config.admin.inc does not ensure that a file_unmanaged_delete operation occurs. Therefore, many archives could persist: config.tar.gz, config_0.tar.gz, config_1.tar.gz, etc. There is a separate config.module issue that could allow remote access by an anonymous user, but only for the one filename config.tar.gz. |
| Weaknesses | CWE-459 | |
| References |
|
Fri, 09 Oct 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient Protection of Configuration Exports in Backdrop CMS |
Fri, 09 Oct 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. | |
| First Time appeared |
Backdropcms
Backdropcms backdrop |
|
| Weaknesses | CWE-497 | |
| CPEs | cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Backdropcms
Backdropcms backdrop |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-09T06:44:26.529Z
Reserved: 2026-10-09T05:18:25.745Z
Link: CVE-2026-107914
No data.
Status : Received
Published: 2026-10-09T06:17:12.777
Modified: 2026-10-09T07:17:18.240
Link: CVE-2026-107914
No data.
OpenCVE Enrichment
Updated: 2026-10-09T09:00:03Z