Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-77136: Powermail form lets attackers read data and run code

CVE-2026-77136 · published 1 month ago
Summary

The Powermail form add‑on processes the sender name field without checking it. A person can submit specially crafted text that makes the server reveal its settings, source code, or even run commands. Update Powermail to the latest release or change the form so the sender name is not used as raw input.

What to do
  • Update typo3 extension "powermail" to version 13.2.1 or later.
Affected software
VendorProductAffected versions
typo3 extension "powermail" < 13.2.1
Original advisory text
Server-Side Template Injection in extension "powermail" (powermail)
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and application source, and potentially remote code execution. Exploitation requires only that a form field is configured as the sender_name field, a common and default-adjacent Powermail configuration. No authentication or user interaction beyond a normal form submission is required. This vulnerability is reported to be actively exploited in the wild.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.5 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published25 Aug 2026
Updated9 Oct 2026
First seen25 Aug 2026
Sources
CVE-2026-77136 · MITRE
Track software like this
Free during beta