Access Control Vulnerability in TYPO3 Affects User Group Assignments
CVE-2026-46721
6.9MEDIUM
Key Information:
- Vendor
Typo3
- Vendor
- CVE Published:
- 19 May 2026
What is CVE-2026-46721?
This vulnerability in TYPO3 allows unauthorized users to manipulate user properties during the account creation and editing processes. Without proper restrictions in place, an attacker can assign themselves or other accounts to privileged frontend user groups, thereby gaining access to sensitive content and functionality that should be restricted. It is crucial for TYPO3 users to ensure their systems are updated and to review user permissions and security settings to mitigate this risk.
Affected Version(s)
Extension "Frontend User Registration" 14.0.0 < 14.0.2
Extension "Frontend User Registration" 0 < 13.2.4
