Vulnerability Description
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-77131?
CVE-2026-77131 is a documented vulnerability. When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SY...
How severe is CVE-2026-77131?
CVSS scoring is not yet available for CVE-2026-77131. Check NVD for updates.
Is there a patch for CVE-2026-77131?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.