CVE-2026-107914
HIGH
NVD
CVSS Score
7.8
Severity
HIGH
Published
Oct 09, 2026
Vendor
unknown
Description
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.