rootpwn

high · CVSS v3 5.9 · CVSS v4 8.2

CVE-2026-104476

Backdrop CMS versions prior to 1.35.1 expose configuration export archives that remain on the server. An unauthenticated attacker can downlo

Overview

Backdrop CMS versions prior to 1.35.1 expose configuration export archives that remain on the server. An unauthenticated attacker can download these archives and view full site configuration, including sensitive settings. This vulnerability can leak administrative credentials and other secrets.

Description

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.

Impact

Confidentiality: The vulnerability allows disclosure of site configuration, potentially revealing admin credentials, database passwords, and other secrets. Integrity: Not directly affected. Availability: Not affected. Defenders: Site administrators and security teams must ensure configuration archives are removed or protected.

Remediation

Apply the official patch to upgrade to Backdrop CMS 1.35.1 or later. If upgrade is not possible, delete any configuration export archives from the server or restrict web access to the export directory. Ensure file permissions prevent public read access.

Risk context

High severity with a CVSS v4 score of 8.2 indicates significant risk. Immediate attention is recommended, especially for sites that have left export archives accessible.

Affected products

  • Backdrop CMS

Scores

Severity
high
CVSS v2
5.4
CVSS v3
5.9
CVSS v4
8.2
EPSS
—

Backdrop CMS information disclosure configuration export high severity unauthenticated file disclosure

← All CVEs