Invitation Controller Vulnerability in TYPO3 Extension by TYPO3
CVE-2026-77146

8.3HIGH

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-77146?

The TYPO3 extension's invitation controller lacks proper input validation, allowing an unauthenticated attacker to bypass security measures. If the input is invalid—such as a missing hash, or referencing an account that does not exist, is disabled, or has been deleted—the system should halt further processing. However, due to this flaw, attackers can exploit the vulnerability to reset passwords and re-enable existing frontend user accounts at will. This exposure is specifically found in the 8.x versions of the extension, making it critical for users to apply necessary patching to safeguard accounts.

Affected Version(s)

Extension "femanager" 8.0.0 < 8.4.2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Steffen Keuper
in2code
.