CVE-2026-77131

Severity CVSS v4.0:
MEDIUM
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
25/08/2026
Last modified:
26/08/2026

Description

When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

References to Advisories, Solutions, and Tools