Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-024 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension. | |
| Title | Broken Access Control in extension "femanager" (femanager) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:31.815Z
Reserved: 2026-08-20T13:10:15.962Z
Link: CVE-2026-77146
No data.
Status : Received
Published: 2026-08-25T09:17:35.820
Modified: 2026-08-25T09:17:35.820
Link: CVE-2026-77146
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:45:03Z