CVE-2026-77132 Details
Description
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.
A vulnerability exists in TYPO3 CMS within the backend localization wizard's AJAX routes, where authorization checks are not properly enforced. This flaw enables authenticated, low-privileged backend users to access records and content elements beyond their authorized scope. The issue is present in TYPO3 CMS versions 10.0.0 prior to 10.4.60, 11.0.0 prior to 11.5.54, 12.0.0 prior to 12.4.49, 13.0.0 prior to 13.4.35, and 14.0.0 prior to 14.3.7.
Update TYPO3 to version 10.4.60 ELTS, 11.5.54 ELTS, 12.4.49 ELTS, 13.4.35 LTS, or 14.3.7 LTS.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TYPO3/typo3/commit/1c63ce806d1ccac839f4aa54ac7f48a22dd7ea64 | TYPO3 | Source CodeVendor |
| https://github.com/TYPO3/typo3/commit/35e070fc654def838fbdc45562c2c095d44ca086 | TYPO3 | Source CodeVendor |
| https://github.com/TYPO3/typo3/commit/c232421325bd18fc4d13efac0fc018a57da2dcd6 | TYPO3 | Source CodeVendor |
| https://news.typo3.com/security/advisory/typo3-core-sa-2026-022 | TYPO3 | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | TYPO3 |
| CWE-862 | Missing Authorization | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 | >= 10.0.0, <= 10.4.59 (semver) >= 11.0.0, <= 11.5.53 (semver) >= 12.0.0, <= 12.4.48 (semver) >= 13.0.0, <= 13.4.34 (semver) >= 14.0.0, <= 14.3.6 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | TYPO3 |
Volerion