PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77137 TYPO3 CVE debrief

The TYPO3 extension 'Forms Export' is vulnerable to SQL injection. A low-privileged backend user with read access to the 'Forms Export' backend module can inject arbitrary SQL through a URL parameter. This issue has been publicly disclosed and patched. The vulnerability allows for potential data tampering or unauthorized access. Defenders should assess exposure and prioritize patching to prevent exploitation. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.7.

Vendor
TYPO3
Product
Extension "Forms Export"
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-28
Advisory published
2026-08-25
Advisory updated
2026-09-28

Who should care

Defenders responsible for TYPO3 installations with the 'Forms Export' extension should assess exposure and prioritize patching to prevent potential SQL injection attacks. Low-privileged backend users with read access to the 'Forms Export' backend module can inject arbitrary SQL through a URL parameter. Defenders should verify the patch status of the 'Forms Export' extension and restrict access to the backend module to prevent exploitation.

Why it matters

CVE-2026-77137 is a SQL injection vulnerability in the TYPO3 extension 'Forms Export'. Low-privileged backend users with read access to the 'Forms Export' backend module can inject arbitrary SQL through a URL parameter. Defenders should prioritize patching and restrict access to the backend module to prevent potential exploitation.

  • Low-privileged users can inject malicious SQL, potentially leading to data tampering or unauthorized access.
  • Successful exploitation requires read access to the 'Forms Export' backend module.
  • Defenders should verify the patch status of the 'Forms Export' extension and restrict access to the backend module.
  • Further investigation is needed to determine the full scope of affected versions and potential impact.

Technical summary

The TYPO3 extension 'Forms Export' fails to properly sanitize user input before using it in a database query, allowing a low-privileged backend user to inject arbitrary SQL through a URL parameter within the 'Forms Export' backend module. This issue has been publicly disclosed and patched. The vulnerability has a CVSS score of 7.7 and is considered HIGH severity. Defenders should prioritize patching this vulnerability to prevent potential SQL injection attacks. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and the affected product.

Defensive priority

Defenders should prioritize patching this vulnerability, as it can be exploited by low-privileged users to inject malicious SQL.

Recommended defensive actions

  • Patch the TYPO3 extension 'Forms Export' to the latest version
  • Restrict access to the 'Forms Export' backend module to authorized users only
  • Monitor for suspicious SQL queries and implement additional security measures to prevent exploitation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.7 and the affected product, TYPO3 extension 'Forms Export'. The vulnerability has been publicly disclosed and patched. The CVE record was published on 2026-08-25T09:17:34.343Z and has not been modified since then. The NVD entry is currently Deferred. Defenders should verify the patch status of the 'Forms Export' extension and restrict access to the backend module.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77137 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77137

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77137 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77137

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://typo3.org/security/advisory/typo3-ext-sa-2026-027

    f4fb688c-4412-4426-b4b8-421ecf27b14a

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.