๐Ÿ” CVE Alert

CVE-2026-77140

UNKNOWN 0.0

Broken Access Control in extension "Telephone Directory" (telephonedirectory)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check.

CWE CWE-862 CWE-639
Vendor typo3
Product extension "telephone directory"
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 extension "telephone directory"

Be the first to know when new unknown vulnerabilities affecting typo3 extension "telephone directory" are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TYPO3 / Extension "Telephone Directory"
0 < 6.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
typo3.org: https://typo3.org/security/advisory/typo3-ext-sa-2026-018

Credits

๐Ÿ” Seungbin Yang Hoja Mustaffa Abdul Latheef