Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...
zetlyn/cve-ghsa vulnerability ghsa GHSA-62pf-58wj-9727 cve CVE-2026-104476 known 2026-10-03
https://github.com/advisories/GHSA-62pf-58wj-9727
Properties
| cvss | 5.9receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-104476",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-200",
"name": "Exposure of Sensitive Information to an Unauthorized Actor"
}
],
"description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
"ghsa_id": "GHSA-62pf-58wj-9727",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-62pf-58wj-9727"
},
{
"type": "CVE",
"value": "CVE-2026-104476"
}
],
"nvd_published_at": "2026-10-03T00:16:35Z",
"published_at": "2026-10-03T00:31:14Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
"https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
"https://backdropcms.org/security/backdrop-sa-core-2026-006",
"https://github.com/backdrop/backdrop",
"https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
"https://github.com/advisories/GHSA-62pf-58wj-9727"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
"type": "unreviewed",
"updated_at": "2026-10-03T00:31:15Z",
"url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-200receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-104476",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-200",
"name": "Exposure of Sensitive Information to an Unauthorized Actor"
}
],
"description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
"ghsa_id": "GHSA-62pf-58wj-9727",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-62pf-58wj-9727"
},
{
"type": "CVE",
"value": "CVE-2026-104476"
}
],
"nvd_published_at": "2026-10-03T00:16:35Z",
"published_at": "2026-10-03T00:31:14Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
"https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
"https://backdropcms.org/security/backdrop-sa-core-2026-006",
"https://github.com/backdrop/backdrop",
"https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
"https://github.com/advisories/GHSA-62pf-58wj-9727"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
"type": "unreviewed",
"updated_at": "2026-10-03T00:31:15Z",
"url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | high From 7.0 to 8.9. receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-104476",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-200",
"name": "Exposure of Sensitive Information to an Unauthorized Actor"
}
],
"description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
"ghsa_id": "GHSA-62pf-58wj-9727",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-62pf-58wj-9727"
},
{
"type": "CVE",
"value": "CVE-2026-104476"
}
],
"nvd_published_at": "2026-10-03T00:16:35Z",
"published_at": "2026-10-03T00:31:14Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
"https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
"https://backdropcms.org/security/backdrop-sa-core-2026-006",
"https://github.com/backdrop/backdrop",
"https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
"https://github.com/advisories/GHSA-62pf-58wj-9727"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
"type": "unreviewed",
"updated_at": "2026-10-03T00:31:15Z",
"url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.