CVE-2026-77131

Summary

When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

Affected Software

VendorProductVersion RangeStatus
TYPO3Extension “SYSSY - TYPO3 Monitoring & Security Checks”0 < 3.0.6affected

Weaknesses

  • CWE-319: CWE-319 Cleartext Transmission of Sensitive Information

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References