CVE-2026-77127
Received Received - Intake

TYPO3 Extension Inline Editing Information Disclosure

Vulnerability report for CVE-2026-77127, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: TYPO3

Description

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error response that discloses the current database value of the requested field, leading to disclosure of sensitive information such as backend and frontend user password hashes. Exploitation requires a valid, authenticated TYPO3 backend user account with access to the extensions backend module.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
typo3 modules to 7.10.4 (exc)
typo3 modules From 8.0.0 (inc) to 8.1.4 (exc)
typo3 modules to 8.1.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information disclosure issue in the TYPO3 extension 'Modules'. It allows an authenticated low-privileged backend user to access sensitive database values through an unrestricted AJAX endpoint. The flaw enables disclosure of backend and frontend user password hashes by manipulating table, field, and record parameters.

Detection Guidance

Check if the TYPO3 extension 'Modules' is installed and if its version is 7.10.3 or below, or between 8.0.0 and 8.1.3. Review backend user permissions for access to the extension's module. Monitor for unusual AJAX endpoint requests or error responses revealing sensitive data.

Impact Analysis

An attacker with a valid low-privileged backend account could exploit this to access sensitive data like password hashes. This could lead to unauthorized access to user accounts, potential privilege escalation, and further compromise of the TYPO3 system.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of personal data, including user credentials. This may violate GDPR's data protection principles and HIPAA's security requirements, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Update the 'Modules' extension to version 7.10.4 or 8.1.4 immediately. Restrict backend user permissions to only necessary modules and fields. Review and remove any unnecessary backend user accounts with access to the extension.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77127. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart