PT-2026-41867 · Typo3 · Crawler Extension

Roman Hergenreder

·

Published

2026-05-19

·

Updated

2026-05-19

·

CVE-2026-8727

CVSS v4.0

7.1

High

VectorAV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions TYPO3 Crawler extension (affected versions not specified)
Description The Crawler extension is subject to Remote Code Execution via PHP Object Injection. This occurs because the extension passes the "X-T3Crawler-Meta" response header from crawled URLs directly to the PHP unserialize() function. An attacker who controls a crawled endpoint can inject arbitrary serialized PHP objects to execute code on the server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl through a Scheduler task.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8727

Affected Products

Crawler Extension