Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-015 |
|
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key. | |
| Title | Insufficient Session Expiration in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy) | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T14:51:54.258Z
Reserved: 2026-08-20T13:10:12.062Z
Link: CVE-2026-77130
Updated: 2026-08-25T14:46:16.424Z
Status : Received
Published: 2026-08-25T09:17:33.360
Modified: 2026-08-25T15:16:44.097
Link: CVE-2026-77130
No data.
OpenCVE Enrichment
Updated: 2026-08-25T11:00:13Z
-
CWE-613
Insufficient Session Expiration