πŸ” CVE Alert

CVE-2026-77132

UNKNOWN 0.0

TYPO3 CMS - Information Disclosure via Backend Localization Wizard

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account.Β This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.

CWE CWE-862 CWE-200
Vendor typo3
Product typo3 cms
Published Sep 8, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 typo3 cms

Be the first to know when new unknown vulnerabilities affecting typo3 typo3 cms are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

TYPO3 / TYPO3 CMS
10.0.0 < 10.4.60 11.0.0 < 11.5.54 12.0.0 < 12.4.49 13.0.0 < 13.4.35 14.0.0 < 14.3.7

References

NVD β†— CVE.org β†— EPSS Data β†—
news.typo3.com: https://news.typo3.com/security/advisory/typo3-core-sa-2026-022 github.com: https://github.com/TYPO3/typo3/commit/c232421325bd18fc4d13efac0fc018a57da2dcd6 github.com: https://github.com/TYPO3/typo3/commit/35e070fc654def838fbdc45562c2c095d44ca086 github.com: https://github.com/TYPO3/typo3/commit/1c63ce806d1ccac839f4aa54ac7f48a22dd7ea64

Credits

πŸ” Oliver Hader πŸ” Antariksha Akhilesh sharma πŸ” β€œkei” πŸ” David GΓ³mez Bru πŸ” KhΖ°Ζ‘ng Anh πŸ” Miro Hatachi πŸ” Phan Long πŸ” HDWSec πŸ” El Mostafa Noujad Benjamin Kott