Access Control Vulnerability in TYPO3 Affects User Group Assignments
CVE-2026-46721

6.9MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
19 May 2026

What is CVE-2026-46721?

This vulnerability in TYPO3 allows unauthorized users to manipulate user properties during the account creation and editing processes. Without proper restrictions in place, an attacker can assign themselves or other accounts to privileged frontend user groups, thereby gaining access to sensitive content and functionality that should be restricted. It is crucial for TYPO3 users to ensure their systems are updated and to review user permissions and security settings to mitigate this risk.

Affected Version(s)

Extension "Frontend User Registration" 14.0.0 < 14.0.2

Extension "Frontend User Registration" 0 < 13.2.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seungbin Yang
Sebastian Fischer
.