The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-015 |
|
History
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key. | |
| Title | Insufficient Session Expiration in extension "SYSSY - TYPO3 Monitoring & Security Checks" (syssy) | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:43.390Z
Reserved: 2026-08-20T13:10:12.062Z
Link: CVE-2026-77130
No data.
Status : Received
Published: 2026-08-25T09:17:33.360
Modified: 2026-08-25T09:17:33.360
Link: CVE-2026-77130
No data.
OpenCVE Enrichment
Updated: 2026-08-25T11:00:13Z
Weaknesses