TYPO3 Powermail Fluid Template Injection (CVE-2026-77136)
CVE-2026-77136 Published on August 25, 2026
Server-Side Template Injection in extension "powermail" (powermail)
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and application source, and potentially remote code execution. Exploitation requires only that a form field is configured as the sender_name field, a common and default-adjacent Powermail configuration. No authentication or user interaction beyond a normal form submission is required. This vulnerability is reported to be actively exploited in the wild.
Vulnerability Analysis
CVE-2026-77136 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Affected Versions
TYPO3 Extension "powermail":- Version 13.0.0 and below 13.2.1 is affected.
- Version 11.0.0 and below 12.6.1 is affected.
- Before 10.9.3 is affected.