PT-2026-81236 · Typo3 · Powermail

·

CVE-2026-77136

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions TYPO3 Powermail (affected versions not specified)
Description An issue exists where the extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as a template source without sanitization. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers, which may lead to the disclosure of server configuration, environment variables, and application source, and potentially result in remote code execution. This issue is reported to be actively exploited in the wild.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77136

Affected Products

Powermail