Authentication Bypass Vulnerability in SYSSY Project by TYPO3
CVE-2026-77130

5.3MEDIUM

What is CVE-2026-77130?

A recent vulnerability in the SYSSY project within TYPO3 enables an attacker who possesses a valid API key to authenticate using an expired JWT token due to inadequate validation of the token's expiration. This flaw allows unauthorized access, jeopardizing the security of the system, especially in environments that rely heavily on secure API interactions. Organizations using the SYSSY project should implement necessary checks to mitigate potential risks associated with the exploitation of this vulnerability.

Affected Version(s)

Extension "SYSSY - TYPO3 Monitoring & Security Checks" 0 < 3.0.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ingrid StĂĽrmer
.