TYPO3 SysSy JWT Expiration Validation Bypass
CVE-2026-77130 Published on August 25, 2026
Insufficient Session Expiration in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy)
The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.
Vulnerability Analysis
CVE-2026-77130 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Products Associated with CVE-2026-77130
Want to know whenever a new CVE is published for TYPO3? stack.watch will email you.
Affected Versions
Extension "SYSSY - TYPO3 Monitoring & Security Checks":- Before 3.0.6 is affected.