CVE-2026-77146
Broken Access Control in extension "femanager" (femanager)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.
| CWE | CWE-862 |
| Vendor | typo3 |
| Product | extension "femanager" |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for typo3 extension "femanager"
Be the first to know when new unknown vulnerabilities affecting typo3 extension "femanager" are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TYPO3 / Extension "femanager"
8.0.0 < 8.4.2
References
Credits
๐ Steffen Keuper in2code