🔐 CVE Alert

CVE-2026-77131

UNKNOWN 0.0

Cleartext Transmission of Sensitive Information in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

CWE CWE-319
Vendor typo3
Product extension "syssy - typo3 monitoring & security checks"
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 extension "syssy - typo3 monitoring & security checks"

Be the first to know when new unknown vulnerabilities affecting typo3 extension "syssy - typo3 monitoring & security checks" are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

TYPO3 / Extension "SYSSY - TYPO3 Monitoring & Security Checks"
0 < 3.0.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
typo3.org: https://typo3.org/security/advisory/typo3-ext-sa-2026-015

Credits

Ingrid Stürmer