Backdrop core - Critical - Information Disclosure - BACKDROP-SA-CORE-2026-006
Backdrop CMS doesn't sufficiently protect configuration exports when delivering a compressed archive.
This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.
A CVE has been requested, and this page will be updated as soon as an official number has been issued.
- Backdrop Core 1.35.x versions prior to 1.35.1
- Backdrop Core 1.34.x versions prior to 1.34.5
Backdrop versions 1.33 and prior do not receive security coverage.