Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.

cve CVE-2026-104476 2 sources, 2 claims · Watch

NVD writes:
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings. the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsbackdrop/backdrop
NVD says “backdrop · backdrop”
made_bybackdrop
NVD says “backdrop”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
GitHub advisories5.9
receipt
Source
GitHub advisories
Its words
5.9
Read by
field:cvss.score
Said since
2026-10-03 06:04 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104476",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
  "ghsa_id": "GHSA-62pf-58wj-9727",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62pf-58wj-9727"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104476"
    }
  ],
  "nvd_published_at": "2026-10-03T00:16:35Z",
  "published_at": "2026-10-03T00:31:14Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
    "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
    "https://backdropcms.org/security/backdrop-sa-core-2026-006",
    "https://github.com/backdrop/backdrop",
    "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
    "https://github.com/advisories/GHSA-62pf-58wj-9727"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T00:31:15Z",
  "url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cvss
cvss
NVD5.9
receipt
Source
NVD
Its words
5.9
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-03 06:07 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "backdrop",
            "vendor": "backdrop",
            "versions": [
              {
                "lessThan": "1.35.1",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "1.35.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings."
      }
    ],
    "id": "CVE-2026-104476",
    "lastModified": "2026-10-03T00:16:35.747",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T00:16:35.747",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://backdropcms.org/security/backdrop-sa-core-2026-006"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—
Cwe
cwe
GitHub advisoriesCWE-200
receipt
Source
GitHub advisories
Its words
CWE-200
Read by
field:cwes[].cwe_id
Said since
2026-10-03 06:04 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104476",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
  "ghsa_id": "GHSA-62pf-58wj-9727",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62pf-58wj-9727"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104476"
    }
  ],
  "nvd_published_at": "2026-10-03T00:16:35Z",
  "published_at": "2026-10-03T00:31:14Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
    "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
    "https://backdropcms.org/security/backdrop-sa-core-2026-006",
    "https://github.com/backdrop/backdrop",
    "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
    "https://github.com/advisories/GHSA-62pf-58wj-9727"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T00:31:15Z",
  "url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Product
product
NVDbackdrop
receipt
Source
NVD
Its words
backdrop
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-03 06:07 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "backdrop",
            "vendor": "backdrop",
            "versions": [
              {
                "lessThan": "1.35.1",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "1.35.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings."
      }
    ],
    "id": "CVE-2026-104476",
    "lastModified": "2026-10-03T00:16:35.747",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T00:16:35.747",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://backdropcms.org/security/backdrop-sa-core-2026-006"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
GitHub advisorieshigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-03 06:04 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-104476",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-200",
      "name": "Exposure of Sensitive Information to an Unauthorized Actor"
    }
  ],
  "description": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.",
  "ghsa_id": "GHSA-62pf-58wj-9727",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-62pf-58wj-9727",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-62pf-58wj-9727"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-104476"
    }
  ],
  "nvd_published_at": "2026-10-03T00:16:35Z",
  "published_at": "2026-10-03T00:31:14Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-104476",
    "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749",
    "https://backdropcms.org/security/backdrop-sa-core-2026-006",
    "https://github.com/backdrop/backdrop",
    "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive",
    "https://github.com/advisories/GHSA-62pf-58wj-9727"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...",
  "type": "unreviewed",
  "updated_at": "2026-10-03T00:31:15Z",
  "url": "https://api.github.com/advisories/GHSA-62pf-58wj-9727",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Status
status
NVDReceived
receipt
Source
NVD
Its words
Received
Read by
field:cve.vulnStatus
Said since
2026-10-03 06:07 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "backdrop",
            "vendor": "backdrop",
            "versions": [
              {
                "lessThan": "1.35.1",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "1.35.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings."
      }
    ],
    "id": "CVE-2026-104476",
    "lastModified": "2026-10-03T00:16:35.747",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T00:16:35.747",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://backdropcms.org/security/backdrop-sa-core-2026-006"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDbackdrop
receipt
Source
NVD
Its words
backdrop
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-03 06:07 UTC
Last answered
2026-10-04 12:15 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "backdrop",
            "vendor": "backdrop",
            "versions": [
              {
                "lessThan": "1.35.1",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "1.35.1",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings."
      }
    ],
    "id": "CVE-2026-104476",
    "lastModified": "2026-10-03T00:16:35.747",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "HIGH",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-03T00:16:35.747",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://backdropcms.org/security/backdrop-sa-core-2026-006"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/backdrop-cms-before-1.35.1-information-disclosure-via-configuration-export-archive"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Primary"
      }
    ]
  }
}
—

vulnerability

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers can download compressed archives generated by users with configuration export permission to obtain the full site configuration, including sensitive settings.
zetlyn/cve-nvd · 2026-10-03
cvss 5.9 product backdrop status Received vendor backdrop source
Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows...
zetlyn/cve-ghsa · 2026-10-03
cvss 5.9 cwe CWE-200 severity high source