CVE-2026-8726: SQL Injection in extension "News system" (news)
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8726?
CVE-2026-8726 is classified as a critical vulnerability due to its potential for arbitrary SQL injection.
How do I fix CVE-2026-8726?
To fix CVE-2026-8726, update the TYPO3 News system extension to the latest version which contains the necessary input sanitization fixes.
Who is affected by CVE-2026-8726?
CVE-2026-8726 affects all installations of the TYPO3 News system extension that have not implemented proper input sanitization.
What kind of attack can be performed using CVE-2026-8726?
An unauthenticated attacker can exploit CVE-2026-8726 to perform arbitrary SQL injection attacks through influenced URL parameters.
When was CVE-2026-8726 disclosed?
CVE-2026-8726 was disclosed in 2026 and has since required prompt attention to mitigate the risks associated with SQL injection.