
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1323 is an insecure deserialization vulnerability in the TransportFailure class of the cpsit/typo3-mailqueue extension for TYPO3 CMS. The extension fails to properly define allowed classes when deserializing transport failure metadata, enabling an attacker with write access to the mail spool directory to execute arbitrary untrusted serialized code. Affected versions are all releases before 0.4.5 and versions 0.5.0 through 0.5.1; patched versions are 0.4.5 and 0.5.2. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 5.2 (Medium), with the discrepancy reflecting the local write-access precondition captured in the v4.0 scoring (GitHub Advisory, TYPO3 Advisory).
The root cause is CWE-502 (Deserialization of Untrusted Data): the extension's TransportFailure class deserializes PHP objects from spool files without restricting which classes may be instantiated, allowing a PHP object injection (CAPEC-586) attack. An attacker who can write a crafted, maliciously serialized file to the directory defined by $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'] can cause the application to deserialize it and execute arbitrary code when the mail queue is processed. The precondition — write access to the spool directory — limits opportunistic exploitation but is achievable by any low-privileged authenticated user or process that has been granted filesystem access to that path (GitHub Advisory, TYPO3 Advisory).
Successful exploitation can result in full system compromise: arbitrary code execution in the context of the web server process, with high impact on confidentiality, integrity, and availability of both the vulnerable TYPO3 instance and any subsequently reachable systems. An attacker could exfiltrate sensitive data (database credentials, user PII), modify application content or configuration, or disrupt service availability. Because the code executes server-side, lateral movement to other services accessible from the web server is also possible (GitHub Advisory, Feedly Intelligence).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.018% (0.000180), placing it in a low-probability exploitation tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for write access to the mail spool directory, which reduces the attack surface compared to fully unauthenticated vulnerabilities.
cpsit/typo3-mailqueue extension in a vulnerable version (< 0.4.5 or 0.5.0–0.5.1) via Composer lock files, TYPO3 extension manager exposure, or HTTP response fingerprinting.$GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].$GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'] that do not correspond to legitimate queued mail messages; files with PHP serialization markers (O:, a:, s:) in their content./bin/bash, curl, wget, python, nc) during or shortly after mail queue processing.TransportFailure class; web server access logs showing requests to TYPO3 CLI endpoints or scheduler tasks at unusual times.Update the cpsit/typo3-mailqueue Composer package to version 0.4.5 (for the 0.4.x branch) or 0.5.2 (for the 0.5.x branch), which properly restrict allowed classes during deserialization (TYPO3 Advisory, GitHub Advisory). As an interim workaround, restrict filesystem write permissions on the mail spool directory (transport_spool_filepath) to only the web server process user, preventing unauthorized file placement. Additionally, monitor the spool directory for unexpected file creation and audit which accounts or processes have write access to that path.
The vulnerability was disclosed by eliashaeussler (a maintainer of the CPS-IT/mailqueue repository) via a coordinated TYPO3 security advisory on March 17, 2026. No significant broader media coverage or notable independent researcher commentary beyond the official advisory and standard CVE aggregator entries has been observed (GitHub Advisory, TYPO3 Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."