TYPO3 SysSy JWT Expiration Validation Bypass
CVE-2026-77130 Published on August 25, 2026

Insufficient Session Expiration in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-77130 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."


Products Associated with CVE-2026-77130

Want to know whenever a new CVE is published for TYPO3? stack.watch will email you.

 

Affected Versions

Extension "SYSSY - TYPO3 Monitoring & Security Checks":