CVE-2026-8727: Remote Code Execution in extension "Site Crawler" (crawler)
The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8727?
CVE-2026-8727 has a severity rating of high with a CVSS score of 7.1.
How does CVE-2026-8727 affect TYPO3 Site Crawler?
CVE-2026-8727 allows for remote code execution on TYPO3 servers through the manipulation of the X-T3Crawler-Meta response header.
Who can exploit CVE-2026-8727?
An attacker needs administrative privileges and control over a crawled endpoint to exploit CVE-2026-8727.
How can I fix CVE-2026-8727?
To fix CVE-2026-8727, update the TYPO3 Site Crawler extension to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-8727?
The exploitation of CVE-2026-8727 can lead to remote code execution, potentially compromising the entire TYPO3 server.