Sceawere
Vulnerability Detail
CVE-2026-107914UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Backdrop CMS Configuration Export Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 4h ago
- Vendor
- backdropcms
- Product
- Backdrop
- Attack Type
- CWE-459 Incomplete Cleanup
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-09T06:17:12.777Z",
"pubdate": "2026-10-09T06:17:12.777Z",
"executiveSummary": "This vulnerability involves insufficient protection of configuration exports within Backdrop CMS when generating compressed archives.\nThe issue is classified as an improper access control or insecure data handling vulnerability within the configuration management subsystem.\nAffected versions include Backdrop CMS 1.34 prior to 1.34.5 and 1.35 prior to 1.35.1.\nThe primary risk entails the potential unauthorized access to sensitive system configuration metadata contained within the exported archive.\nExploitation is constrained by a prerequisite requirement: the attacker must either possess or successfully compromise an account with the 'Synchronize, import, and export configuration' permission.\nOnce the export process is triggered, the vulnerability manifests as an inadequacy in the security mechanisms protecting the resulting file, potentially allowing unauthorized retrieval if the path is discovered or if access controls on the temporary directory are misconfigured.\nThe impact depends on the sensitivity of the exported configuration data, which may include database credentials, API keys, or site-specific architecture details.",
"technicalDetails": "The vulnerability resides in the Backdrop CMS configuration management system, specifically within the logic responsible for packaging configuration exports into compressed archive formats (e.g., .tar.gz).\nThe root cause is a deficiency in the security wrappers or file-system permissions applied to the generated archive files during the delivery phase. While the administrative interface performs the generation, the resulting file is not sufficiently isolated or protected from unauthorized access once it resides on the server's filesystem.\nThe attack flow requires an authenticated session where the user has been granted the 'Synchronize, import, and export configuration' administrative permission. An attacker possessing these credentials—or having performed session hijacking against an administrator—initiates the configuration export process. Upon request, the system generates the archive. Due to the lack of strict file-level access controls, the archive is potentially exposed to unauthorized retrieval if an attacker can predict or identify the file path on the web-accessible server directory.\nThe vulnerability does not manifest as a direct RCE but rather as a sensitive data exposure vector. By accessing the configuration export, an attacker gains visibility into the application's internal state. This includes, but is not limited to, active module configurations, site settings, and potentially sensitive environment variables or service integration parameters that are serialized within the YAML configuration files contained in the archive.\nThe risk is elevated because configuration files in CMS environments often contain secrets that facilitate further lateral movement or full platform compromise. Once the archive is retrieved, the attacker can conduct offline analysis to identify vulnerabilities in site architecture, bypass secondary security controls, or extract credentials for external systems integrated with the Backdrop CMS instance.\nBecause the archive is created as part of an authenticated workflow, the vulnerability is strictly tied to the application's session management and existing authorization model. It effectively allows an authorized action to be exploited for unauthorized data exfiltration due to the failure of the underlying infrastructure to enforce 'least privilege' on the generated output files."
}