Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-016 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error response that discloses the current database value of the requested field, leading to disclosure of sensitive information such as backend and frontend user password hashes. Exploitation requires a valid, authenticated TYPO3 backend user account with access to the extensions backend module. | |
| Title | Information Disclosure in extension "Modules" (modules) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:45.715Z
Reserved: 2026-08-20T13:10:12.062Z
Link: CVE-2026-77127
No data.
Status : Received
Published: 2026-08-25T09:17:32.860
Modified: 2026-08-25T09:17:32.860
Link: CVE-2026-77127
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:30:05Z
-
CWE-639
Authorization Bypass Through User-Controlled Key