It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users to access information about records and content elements that fall outside of their permitted range. Exploiting this vulnerability requires a low-privileged backend user account. This issue affects TYPO3 CMS versions 10.0.0-10.4.59, 11.0.0-11.5.53, 12.0.0-12.4.48, 13.0.0-13.4.34 and 14.0.0-14.3.6.
{
"cna_assigner": "TYPO3",
"cwe_ids": [
"CWE-200",
"CWE-862"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77132.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "10.0.0"
},
{
"fixed": "10.4.60"
},
{
"introduced": "11.0.0"
},
{
"fixed": "11.5.54"
},
{
"introduced": "12.0.0"
},
{
"fixed": "12.4.49"
},
{
"introduced": "13.0.0"
},
{
"fixed": "13.4.35"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.3.7"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "10.0.0"
},
{
"fixed": "10.4.60"
},
{
"introduced": "11.0.0"
},
{
"fixed": "11.5.54"
},
{
"introduced": "12.0.0"
},
{
"fixed": "12.4.49"
},
{
"introduced": "13.0.0"
},
{
"fixed": "13.4.35"
},
{
"introduced": "14.0.0"
},
{
"fixed": "14.3.7"
}
],
"source": "CPE_FIELD"
}
]
}