CVE-2026-0895: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-0895 is an insecure deserialization vulnerability in the cpsit/typo3-mailqueue TYPO3 extension, specifically within the QueueableFileTransport class. The extension extends TYPO3's FileSpool component and overwrites the security fix introduced in TYPO3-CORE-SA-2026-004, meaning that even fully patched TYPO3 core installations remain vulnerable when this extension is present. Affected versions are cpsit/typo3-mailqueue < 0.4.3 and >= 0.5.0, < 0.5.1. It carries a CVSS v4 base score of 5.2 (Medium), though the estimated category severity is HIGH due to high subsequent system impact (Github Advisory, Feedly).

Technical details

The root cause is CWE-502 (Deserialization of Untrusted Data). The vulnerable QueueableFileTransport::restoreItem() method used PHP's native unserialize() with a limited allowedClasses allowlist to deserialize mail queue files from disk, rather than using TYPO3 core's hardened PolymorphicDeserializer. When the extension is installed, it replaces the patched core implementation with this unsafe version, re-introducing the deserialization gadget chain attack surface. Exploitation requires local access and low privileges (e.g., write access to the mail spool directory), plus specific deployment conditions (Attack Requirements: Present), making it a local privilege escalation or lateral movement vector rather than a remote code execution path (Github Advisory, Commit fd09aa4).

Impact

Successful exploitation can lead to arbitrary code execution on the host system through a crafted serialized PHP object placed in the mail spool directory. While the vulnerable system itself has low integrity impact and no direct confidentiality or availability impact, the subsequent (downstream) system impact is rated High across confidentiality, integrity, and availability — meaning a compromised TYPO3 application server could be fully taken over, enabling data exfiltration, persistent backdoors, or denial of service. The vulnerability is particularly dangerous in shared hosting or multi-tenant environments where low-privileged users can write to spool directories (Github Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-0895. The EPSS score is approximately 0.072% (22nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and the ability to write a malicious serialized file to the mail spool directory, which limits the attacker pool significantly (Github Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a TYPO3 installation with the cpsit/typo3-mailqueue extension installed (versions < 0.4.3 or 0.5.0 <= version < 0.5.1) and locate the configured mail spool directory on the filesystem.
  2. Gain local access: Obtain low-privileged local access to the server (e.g., via a compromised web application account, SSH access, or another vulnerability) sufficient to write files to the TYPO3 mail spool directory.
  3. Craft malicious payload: Generate a PHP serialized object payload using a known PHP gadget chain (e.g., via tools like PHPGGC) targeting classes available in the TYPO3/Symfony environment.
  4. Place payload in spool: Write the crafted serialized payload as a file in the mail spool directory used by QueueableFileTransport (the directory configured for FileSpool).
  5. Trigger deserialization: Wait for or trigger the mail queue processing routine (e.g., via a TYPO3 scheduler task or CLI command) that calls restoreItem(), which will call unserialize() on the malicious file without adequate class restrictions, executing the gadget chain and achieving arbitrary code execution (Github Advisory, Commit fd09aa4).

Indicators of compromise

  • File System: Unexpected or malformed files in the TYPO3 mail spool directory (e.g., files with unusual sizes, binary content, or PHP serialization markers O: at the start); new or modified PHP files in the TYPO3 installation directory following mail queue processing.
  • Logs: TYPO3 application logs showing SerializedMessageIsInvalid exceptions for files not created by the mail system; PHP error logs indicating unexpected class instantiation during deserialization.
  • Process: Unusual child processes spawned by the PHP-FPM or web server process (e.g., bash, curl, wget, python) following execution of the TYPO3 mail queue scheduler task.
  • Network: Unexpected outbound connections from the web server to external IPs shortly after mail queue processing runs.

Mitigation and workarounds

Update the cpsit/typo3-mailqueue extension to version 0.4.3 (for the 0.4.x branch) or 0.5.1 (for the 0.5.x branch). The fix replaces the unsafe unserialize() call with TYPO3 core's PolymorphicDeserializer, which enforces a strict allowlist of permitted classes. Additionally, ensure the underlying TYPO3 core is updated to at least version 12.4.41 or 13.4.23 (as required by the patched extension). As a temporary workaround, restrict write access to the mail spool directory to only the web server process user, and monitor the directory for unexpected files (Github Advisory, TYPO3 Advisory).

Community reactions

The vulnerability was disclosed by the TYPO3 security team via advisory TYPO3-EXT-SA-2026-001 and credited to the extension maintainer eliashaeussler, who also authored the fix. No significant broader media coverage or notable researcher commentary beyond the official advisory and standard vulnerability database entries has been identified (TYPO3 Advisory, Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management