CVE-2026-77131
Received Received - Intake

TYPO3 Extension SYSSY Information Disclosure via Unencrypted Transmission

Vulnerability report for CVE-2026-77131, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: TYPO3

Description

When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
typo3 syssy to 3.0.6 (exc)
typo3 syssy 3.0.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs when OpenSSL is missing on a server running TYPO3. Instead of encrypting system information, it transmits it in cleartext. An attacker needs prior access to the SYSSY project's API key to exploit this issue.

Detection Guidance

To detect this vulnerability, check if the SYSSY extension versions 3.0.5 or below are installed and if OpenSSL is unavailable on the server. Inspect network traffic for cleartext transmission of TYPO3 system information. Verify if API keys are exposed or transmitted without encryption.

Impact Analysis

An attacker with the API key could intercept and read sensitive TYPO3 system details sent in plaintext. This may lead to further attacks if the exposed information includes configuration weaknesses or secrets.

Compliance Impact

Transmitting sensitive system information in cleartext violates encryption requirements under GDPR and HIPAA. This could result in non-compliance, potential fines, and increased exposure to data breaches.

Mitigation Strategies

Ensure OpenSSL is available and properly configured on the server to encrypt TYPO3 system information transmission. Verify API key security for SYSSY projects to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77131. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart