๐Ÿ” CVE Alert

CVE-2026-77141

UNKNOWN 0.0

Broken Access Control in extension "Club Directory" (clubdirectory)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a club record can send a direct request to the update or activate action and overwrite that record, or publish one still awaiting approval, without owning it.

Vendor typo3
Product extension "club directory"
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for typo3 extension "club directory"

Be the first to know when new unknown vulnerabilities affecting typo3 extension "club directory" are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—