Junglewise Threat Intelligence

CVE-2026-77138: TYPO3 HTML5 Video Player vs. Powermail extension remote code execution

CVE-2026-77138 · Severity: info · CVSS 9.8 · Published 2026-08-25

Vendors: Typo3.

Executive brief

The "HTML5 Video Player vs. Powermail" extension for TYPO3 improperly deserializes untrusted cookie data without validation, allowing an unauthenticated attacker to inject malicious serialized objects. An attacker can exploit this vulnerability to achieve arbitrary code execution on the web server, gaining complete control over the TYPO3 installation and any data it manages.

Technical details

The vulnerability is a PHP Object Injection issue (CWE-502) caused by passing attacker-controlled cookie input directly to PHP's unserialize() function without sanitization or validation. An unauthenticated remote attacker with network access can craft a malicious serialized payload and deliver it via a cookie header to trigger object instantiation gadget chains, achieving Remote Code Execution. The vulnerable component processes untrusted client input during the deserialization step with no access control required. The extension (lochmueller/html5videoplayer-powermail) has been deprecated and is no longer maintained; affected versions 0.2.1 and below have been removed from the TYPO3 Extension Repository.

Affected products

  • TYPO3 HTML5 Video Player vs. Powermail extension 0.2.1 and below

Timeline

  • 2026-08-25: disclosed

References