
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0895 is an insecure deserialization vulnerability in the cpsit/typo3-mailqueue TYPO3 extension, specifically within the QueueableFileTransport class. The extension extends TYPO3's FileSpool component and overwrites the security fix introduced in TYPO3-CORE-SA-2026-004, meaning that even fully patched TYPO3 core installations remain vulnerable when this extension is present. Affected versions are cpsit/typo3-mailqueue < 0.4.3 and >= 0.5.0, < 0.5.1. It carries a CVSS v4 base score of 5.2 (Medium), though the estimated category severity is HIGH due to high subsequent system impact (Github Advisory, Feedly).
The root cause is CWE-502 (Deserialization of Untrusted Data). The vulnerable QueueableFileTransport::restoreItem() method used PHP's native unserialize() with a limited allowedClasses allowlist to deserialize mail queue files from disk, rather than using TYPO3 core's hardened PolymorphicDeserializer. When the extension is installed, it replaces the patched core implementation with this unsafe version, re-introducing the deserialization gadget chain attack surface. Exploitation requires local access and low privileges (e.g., write access to the mail spool directory), plus specific deployment conditions (Attack Requirements: Present), making it a local privilege escalation or lateral movement vector rather than a remote code execution path (Github Advisory, Commit fd09aa4).
Successful exploitation can lead to arbitrary code execution on the host system through a crafted serialized PHP object placed in the mail spool directory. While the vulnerable system itself has low integrity impact and no direct confidentiality or availability impact, the subsequent (downstream) system impact is rated High across confidentiality, integrity, and availability — meaning a compromised TYPO3 application server could be fully taken over, enabling data exfiltration, persistent backdoors, or denial of service. The vulnerability is particularly dangerous in shared hosting or multi-tenant environments where low-privileged users can write to spool directories (Github Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-0895. The EPSS score is approximately 0.072% (22nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and the ability to write a malicious serialized file to the mail spool directory, which limits the attacker pool significantly (Github Advisory, Feedly).
cpsit/typo3-mailqueue extension installed (versions < 0.4.3 or 0.5.0 <= version < 0.5.1) and locate the configured mail spool directory on the filesystem.QueueableFileTransport (the directory configured for FileSpool).restoreItem(), which will call unserialize() on the malicious file without adequate class restrictions, executing the gadget chain and achieving arbitrary code execution (Github Advisory, Commit fd09aa4).O: at the start); new or modified PHP files in the TYPO3 installation directory following mail queue processing.SerializedMessageIsInvalid exceptions for files not created by the mail system; PHP error logs indicating unexpected class instantiation during deserialization.bash, curl, wget, python) following execution of the TYPO3 mail queue scheduler task.Update the cpsit/typo3-mailqueue extension to version 0.4.3 (for the 0.4.x branch) or 0.5.1 (for the 0.5.x branch). The fix replaces the unsafe unserialize() call with TYPO3 core's PolymorphicDeserializer, which enforces a strict allowlist of permitted classes. Additionally, ensure the underlying TYPO3 core is updated to at least version 12.4.41 or 13.4.23 (as required by the patched extension). As a temporary workaround, restrict write access to the mail spool directory to only the web server process user, and monitor the directory for unexpected files (Github Advisory, TYPO3 Advisory).
The vulnerability was disclosed by the TYPO3 security team via advisory TYPO3-EXT-SA-2026-001 and credited to the extension maintainer eliashaeussler, who also authored the fix. No significant broader media coverage or notable researcher commentary beyond the official advisory and standard vulnerability database entries has been identified (TYPO3 Advisory, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."