Junglewise Threat Intelligence

CVE-2026-77132: TYPO3 CMS authorization bypass in localization AJAX endpoints

CVE-2026-77132 · Severity: info · Published 2026-09-08

Vendors: Typo3.

Executive brief

TYPO3 CMS is a popular open-source web content management system used to build and manage websites. Several backend wizard endpoints used for content localization failed to properly verify that users had permission to access the pages they were requesting information about. A low-privileged backend user could exploit this to view sensitive information about pages, content records, and their structure that they should not have access to.

Technical details

An authorization bypass vulnerability exists in three AJAX localization endpoints (getUsedLanguagesInPage(), getRecordLocalizeSummary(), and localizeRecords()) in the TYPO3 backend. These endpoints failed to verify that the authenticated backend user had permission to access the pages their target records belonged to. The vulnerability allows an authenticated low-privileged backend user to disclose page language configurations, record titles, UIDs, and backend layout column information that falls outside their permitted access range. The vulnerability is exploited by making AJAX requests to these endpoints while authenticated. Patches are available and have been released for affected versions.

Affected products

  • TYPO3 CMS 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34, 14.0.0-14.3.6

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched

References