Remote Code Execution Vulnerability in TYPO3 Repository Extension
CVE-2026-77128
6.3MEDIUM
Key Information:
- Vendor
Typo3
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-77128?
The TYPO3 Repository Extension contains a vulnerability that allows an unauthenticated remote user to bypass restrictions on querying event visibility. Specifically, if the disableOverrideDemand setting is not enabled, attackers can use a demand-override parameter to access hidden or time-restricted events, potentially exposing sensitive information. This vulnerability requires careful configuration management to mitigate the risk of unauthorized access.
Affected Version(s)
Extension "Event management and registration" 9.0.0 < 9.0.3
Extension "Event management and registration" 8.0.0 < 8.6.2
Extension "Event management and registration" 7.0.0 < 7.9.3
