high · CVSS v3 5.9 · CVSS v4 8.2
CVE-2026-104476
Backdrop CMS versions prior to 1.35.1 expose configuration export archives that remain on the server. An unauthenticated attacker can downlo
Overview
Backdrop CMS versions prior to 1.35.1 expose configuration export archives that remain on the server. An unauthenticated attacker can download these archives and view full site configuration, including sensitive settings. This vulnerability can leak administrative credentials and other secrets.
Description
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
Impact
Confidentiality: The vulnerability allows disclosure of site configuration, potentially revealing admin credentials, database passwords, and other secrets. Integrity: Not directly affected. Availability: Not affected. Defenders: Site administrators and security teams must ensure configuration archives are removed or protected.
Remediation
Apply the official patch to upgrade to Backdrop CMS 1.35.1 or later. If upgrade is not possible, delete any configuration export archives from the server or restrict web access to the export directory. Ensure file permissions prevent public read access.
Risk context
High severity with a CVSS v4 score of 8.2 indicates significant risk. Immediate attention is recommended, especially for sites that have left export archives accessible.
Affected products
- Backdrop CMS
Scores
- Severity
- high
- CVSS v2
- 5.4
- CVSS v3
- 5.9
- CVSS v4
- 8.2
- EPSS
- —