PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77136 TYPO3 CVE debrief

CVE-2026-77136 is a critical vulnerability in an extension for Typo3, allowing an unauthenticated attacker to execute arbitrary Fluid ViewHelpers, potentially leading to disclosure of server configuration, environment variables, and application source, and possibly remote code execution. The vulnerability is reported to be actively exploited in the wild.

Vendor
TYPO3
Product
Powermail extension
CVSS
CRITICAL 9.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-28
Advisory published
2026-08-25
Advisory updated
2026-09-28

Who should care

Administrators and developers using Typo3 with the affected extension should assess exposure and take immediate action to prevent exploitation. This includes verifying extension configurations, specifically checking for the 'sender_name' field in Powermail configurations, and monitoring for suspicious activity. Security teams and vulnerability management teams should prioritize verification and mitigation efforts.

Why it matters

CVE-2026-77136 is a critical vulnerability in a Typo3 extension that allows unauthenticated attackers to execute arbitrary Fluid ViewHelpers, potentially leading to disclosure of sensitive information and remote code execution. Defenders should prioritize verification of extension configurations, input validation, and monitoring for suspicious activity.

  • Potential disclosure of server configuration, environment variables, and application source
  • Possible remote code execution
  • Required verification of Typo3 extension configurations and input validation
  • Need for monitoring and detection of suspicious activity

Technical summary

The extension passes the raw value of a form field directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers, potentially leading to disclosure of server configuration, environment variables, and application source, and possibly remote code execution. This occurs when a form field is configured as the sender_name field, a common and default-adjacent Powermail configuration in Typo3. No authentication or user interaction beyond a normal form submission is required for exploitation.

Defensive priority

High

Recommended defensive actions

  • Review and update Typo3 extension configurations to prevent exploitation
  • Implement input validation and sanitization for form fields
  • Monitor for suspicious activity and potential exploitation attempts
  • Verify affected Typo3 deployments exist in managed environments
  • Plan vendor-supported updates or mitigations through normal change control
  • Review compensating controls for exposed systems while remediation is scheduled
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its CVSS score and vector. A source reference from Typo3 provides additional context on the vulnerability. Evidence is limited to public sources and may not reflect the full scope of affected systems or exploitation details. Defenders should verify extension configurations, specifically checking for the 'sender_name' field in Powermail configurations, and monitor for suspicious activity. The CVE Program and NVD entries are considered authoritative,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77136 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77136

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77136 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77136

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://typo3.org/security/advisory/typo3-ext-sa-2026-022

    f4fb688c-4412-4426-b4b8-421ecf27b14a

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.