Description
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.
Published: 2026-08-25
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time‑restricted events, unless the disableOverrideDemand plugin setting is active. The flaw, categorized as CWE‑862, allows bypassing intended access controls and exposing event data that should remain confidential or time‑locked.

Affected Systems

The affected product is the Event management and registration extension (sf_event_mgt) for TYPO3. No specific version information is disclosed in the advisory, but any installation of this extension that has not applied the vendor’s recent fix is vulnerable.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. EPSS is not available, so quantitative exploitation probability cannot be determined. Because the attack requires only a crafted HTTP request with the override parameter and does not need authentication, the attacker can remotely gain access to unprotected event records. As the issue is not listed in the CISA KEV catalog, it has not yet been observed in widespread exploitation, but the potential impact warrants cautious mitigation.

Generated by OpenCVE AI on August 25, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Activate the disableOverrideDemand setting in the "Event management and registration" extension’s configuration to block overridden demand parameters.
  • Apply the latest patch or upgrade the "Event management and registration" extension to the version that resolves the access‑control flaw.
  • Verify that protected or hidden events are no longer visible to unauthenticated users by testing with sample requests.

Generated by OpenCVE AI on August 25, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.
Title Broken Access Control in extension "Event management and registration" (sf_event_mgt)
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-08-25T09:00:44.929Z

Reserved: 2026-08-20T13:10:12.062Z

Link: CVE-2026-77128

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T09:17:33.033

Modified: 2026-08-25T09:17:33.033

Link: CVE-2026-77128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T10:30:05Z

Weaknesses