SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77132

MEDIUM · CVSS 5.3 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Several versions of TYPO3 CMS are vulnerable due to insufficient authorization checks in AJAX routes used for the backend localization wizard, allowing low-privileged authenticated users to access unauthorized records and content elements. This could lead to unauthorized information disclosure within the system. Organizations using affected TYPO3 versions should prioritize remediation to mitigate the risk of data exposure from compromised low-privileged accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77132
Severity
MEDIUM
CVSS
5.3
EPSS
0.41%

Original NVD Description

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.