Description
It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A series of AJAX endpoints used by the backend localization wizard failed to enforce proper authorization checks. As a result, users who could authenticate to the TYPO3 backend but had only low‑privileged roles could retrieve records and content elements that they normally had no permission to view. The flaw does not allow code execution or privilege escalation; it only reduces confidentiality by exposing data to unauthorized backend users.

Affected Systems

TYPO3 CMS versions 10.0.0 through 10.4.59, 11.0.0 through 11.5.53, 12.0.0 through 12.4.48, 13.0.0 through 13.4.34, and 14.0.0 through 14.3.6 are affected.

Risk and Exploitability

The CVSS metric of 5.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is unknown but could be low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate backend account with low privileges, making the attack internally focused on exposed confidential data rather than external compromise.

Generated by OpenCVE AI on September 8, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TYPO3 CMS to a patched release that addresses the missing authorization checks in the localization wizard.
  • Verify that all backend user accounts have the minimum privileges required for their roles and audit existing permissions for over‑privileged users.
  • Monitor backend access logs for unusual requests to localization‑related AJAX routes and remediate any unauthorized access discovered.

Generated by OpenCVE AI on September 8, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.
Title TYPO3 CMS - Information Disclosure via Backend Localization Wizard
First Time appeared Typo3
Typo3 typo3
Weaknesses CWE-200
CWE-862
CPEs cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Vendors & Products Typo3
Typo3 typo3
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-09-08T12:22:01.555Z

Reserved: 2026-08-20T13:10:12.062Z

Link: CVE-2026-77132

cve-icon Vulnrichment

Updated: 2026-09-08T12:21:49.246Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T10:17:13.803

Modified: 2026-09-08T19:15:18.627

Link: CVE-2026-77132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T11:00:10Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-862

    Missing Authorization