CVE-2026-1323: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-1323 is an insecure deserialization vulnerability in the TransportFailure class of the cpsit/typo3-mailqueue extension for TYPO3 CMS. The extension fails to properly define allowed classes when deserializing transport failure metadata, enabling an attacker with write access to the mail spool directory to execute arbitrary untrusted serialized code. Affected versions are all releases before 0.4.5 and versions 0.5.0 through 0.5.1; patched versions are 0.4.5 and 0.5.2. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 5.2 (Medium), with the discrepancy reflecting the local write-access precondition captured in the v4.0 scoring (GitHub Advisory, TYPO3 Advisory).

Technical details

The root cause is CWE-502 (Deserialization of Untrusted Data): the extension's TransportFailure class deserializes PHP objects from spool files without restricting which classes may be instantiated, allowing a PHP object injection (CAPEC-586) attack. An attacker who can write a crafted, maliciously serialized file to the directory defined by $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'] can cause the application to deserialize it and execute arbitrary code when the mail queue is processed. The precondition — write access to the spool directory — limits opportunistic exploitation but is achievable by any low-privileged authenticated user or process that has been granted filesystem access to that path (GitHub Advisory, TYPO3 Advisory).

Impact

Successful exploitation can result in full system compromise: arbitrary code execution in the context of the web server process, with high impact on confidentiality, integrity, and availability of both the vulnerable TYPO3 instance and any subsequently reachable systems. An attacker could exfiltrate sensitive data (database credentials, user PII), modify application content or configuration, or disrupt service availability. Because the code executes server-side, lateral movement to other services accessible from the web server is also possible (GitHub Advisory, Feedly Intelligence).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.018% (0.000180), placing it in a low-probability exploitation tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for write access to the mail spool directory, which reduces the attack surface compared to fully unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify TYPO3 installations using the cpsit/typo3-mailqueue extension in a vulnerable version (< 0.4.5 or 0.5.0–0.5.1) via Composer lock files, TYPO3 extension manager exposure, or HTTP response fingerprinting.
  2. Obtain spool directory write access: Authenticate to the TYPO3 backend or gain filesystem access (e.g., via a low-privileged CMS account, FTP, or another vulnerability) sufficient to write files to the path configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'].
  3. Craft malicious serialized payload: Generate a PHP serialized object chain (gadget chain) targeting classes available in the TYPO3/Symfony autoloader that, when deserialized, execute arbitrary OS commands (e.g., using tools like PHPGGC to generate a suitable gadget chain).
  4. Write payload to spool directory: Place the crafted serialized file in the mail spool directory, mimicking the naming convention of legitimate spool files so it is picked up by the mail queue processor.
  5. Trigger deserialization: Wait for or trigger the TYPO3 mail queue processing (e.g., via a scheduled task/cron job or by manually invoking the queue flush command), causing the extension to deserialize the malicious file and execute the embedded payload.
  6. Achieve code execution: The injected code runs in the web server process context, enabling reverse shell establishment, credential harvesting, or further lateral movement (GitHub Advisory, TYPO3 Advisory).

Indicators of compromise

  • File System: Unexpected or anomalously named files in the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath'] that do not correspond to legitimate queued mail messages; files with PHP serialization markers (O:, a:, s:) in their content.
  • Process: Unusual child processes spawned by the PHP-FPM or web server process (e.g., /bin/bash, curl, wget, python, nc) during or shortly after mail queue processing.
  • Logs: TYPO3 or PHP error logs showing deserialization errors, unexpected class instantiation warnings, or fatal errors referencing the TransportFailure class; web server access logs showing requests to TYPO3 CLI endpoints or scheduler tasks at unusual times.
  • Network: Unexpected outbound connections from the web server to external IPs following mail queue processing events, potentially indicating reverse shell or data exfiltration activity.

Mitigation and workarounds

Update the cpsit/typo3-mailqueue Composer package to version 0.4.5 (for the 0.4.x branch) or 0.5.2 (for the 0.5.x branch), which properly restrict allowed classes during deserialization (TYPO3 Advisory, GitHub Advisory). As an interim workaround, restrict filesystem write permissions on the mail spool directory (transport_spool_filepath) to only the web server process user, preventing unauthorized file placement. Additionally, monitor the spool directory for unexpected file creation and audit which accounts or processes have write access to that path.

Community reactions

The vulnerability was disclosed by eliashaeussler (a maintainer of the CPS-IT/mailqueue repository) via a coordinated TYPO3 security advisory on March 17, 2026. No significant broader media coverage or notable independent researcher commentary beyond the official advisory and standard CVE aggregator entries has been observed (GitHub Advisory, TYPO3 Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management