Backend AJAX Endpoint Vulnerability in TYPO3 Extension
CVE-2026-77127

6MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-77127?

The TYPO3 extension contains a flaw in its backend AJAX endpoint that permits unauthorized access to sensitive database fields. This vulnerability arises because the backend AJAX endpoint fails to adequately restrict inline editing functions to only those fields the user is authorized to view or edit. As a result, a low-privileged authenticated backend user can exploit this weakness by manipulating table and field parameters. This manipulation may trigger an error that reveals confidential information, including backend and frontend user password hashes, posing a significant risk of unauthorized access to the system.

Affected Version(s)

Extension "Modules" 8.0.0 < 8.1.4

Extension "Modules" 0 < 7.10.4

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lim, Han Seop
Thomas Deuling
.