Invitation Controller Vulnerability in TYPO3 Extension by TYPO3
CVE-2026-77146
8.3HIGH
What is CVE-2026-77146?
The TYPO3 extension's invitation controller lacks proper input validation, allowing an unauthenticated attacker to bypass security measures. If the input is invalid—such as a missing hash, or referencing an account that does not exist, is disabled, or has been deleted—the system should halt further processing. However, due to this flaw, attackers can exploit the vulnerability to reset passwords and re-enable existing frontend user accounts at will. This exposure is specifically found in the 8.x versions of the extension, making it critical for users to apply necessary patching to safeguard accounts.
Affected Version(s)
Extension "femanager" 8.0.0 < 8.4.2
