Frontend Editing Vulnerability in TYPO3 Product by TYPO3 GmbH
CVE-2026-77142
8.8HIGH
What is CVE-2026-77142?
The frontend editing feature in TYPO3 relies on a visibility flag to restrict access to editing company records. However, this mechanism fails during server-side write operations. A user can exploit this vulnerability by submitting a crafted update request for a company record they do not own, effectively bypassing ownership validation. This allows unauthorized modification of sensitive data in the application.
Affected Version(s)
Extension "Industry Directory" 0 < 8.1.2
