CVE-2026-77127Disclosure

LOWCVSS 6.0 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error response that discloses the current database value of the requested field, leading to disclosure of sensitive information such as backend and frontend user password hashes. Exploitation requires a valid, authenticated TYPO3 backend user account with access to the extensions backend module.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 2Technical Details · 2026-08-25: 208-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-77127 The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged ba… https://www.cve.org/CVERecord?id=CVE-2026-77127 ----- Traducción: CVE-2026-77127 La … https://infoflow.cloud`

    Post summary

    CVE‑2026‑77127 is disclosed as a mis‑restricted backend AJAX endpoint that permits low‑privileged authenticated users to edit fields they should not have access to.

    00000253
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-77127 The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged ba… https://www.cve.org/CVERecord?id=CVE-2026-77127

    Post summary

    The tweet announces CVE-2026-77127, describing a logic flaw in an extension’s AJAX endpoint that allows unauthorized inline editing, without discussing exploits, patches, or active exploitation.

    000001.0K
    58.0K followersView on X

Explore more