Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...

zetlyn/cve-ghsa vulnerability ghsa GHSA-62pf-58wj-9727 cve CVE-2026-104476 known 2026-10-03

https://github.com/advisories/GHSA-62pf-58wj-9727

Properties

cvss5.9
receipt
Source
GitHub advisories
Its words
5.9
Read by
field:cvss.score
Said since
2026-10-03 06:04 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104476",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
  "ghsa_id": "GHSA-62pf-58wj-9727",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62pf-58wj-9727"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104476"
    }
  ],
  "nvd_published_at": "2026-10-03T00:16:35Z",
  "published_at": "2026-10-03T00:31:14Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
    "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
    "https://backdropcms.org/security/backdrop-sa-core-2026-006",
    "https://github.com/backdrop/backdrop",
    "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
    "https://github.com/advisories/GHSA-62pf-58wj-9727"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T00:31:15Z",
  "url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-200
receipt
Source
GitHub advisories
Its words
CWE-200
Read by
field:cwes[].cwe_id
Said since
2026-10-03 06:04 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104476",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
  "ghsa_id": "GHSA-62pf-58wj-9727",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62pf-58wj-9727"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104476"
    }
  ],
  "nvd_published_at": "2026-10-03T00:16:35Z",
  "published_at": "2026-10-03T00:31:14Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
    "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
    "https://backdropcms.org/security/backdrop-sa-core-2026-006",
    "https://github.com/backdrop/backdrop",
    "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
    "https://github.com/advisories/GHSA-62pf-58wj-9727"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T00:31:15Z",
  "url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severityhigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-03 06:04 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104476",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
  "ghsa_id": "GHSA-62pf-58wj-9727",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62pf-58wj-9727"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104476"
    }
  ],
  "nvd_published_at": "2026-10-03T00:16:35Z",
  "published_at": "2026-10-03T00:31:14Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
    "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
    "https://backdropcms.org/security/backdrop-sa-core-2026-006",
    "https://github.com/backdrop/backdrop",
    "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
    "https://github.com/advisories/GHSA-62pf-58wj-9727"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T00:31:15Z",
  "url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows... Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.