Description
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.
Published: 2026-08-25
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update Extension
AI Analysis

Impact

The femanager extension for TYPO3 does not verify that the requested user record matches the configured or logged‑in target. An attacker with access to the Detail or List plugin can supply any user ID to retrieve that user's name, email, date of birth, and address. The vulnerability allows confidential personal data to be disclosed to unauthenticated or low‑privileged visitors, constituting a high‑severity information‑exposure flaw (CWE‑639).

Affected Systems

Any installation of the femanager extension for TYPO3 is potentially affected. No specific version numbers are listed in the advisory, so the issue likely applies to all current releases until a patch is released.

Risk and Exploitability

The CVSS score of 8.2 indicates a high impact with no authentication required and a network attack vector. Because the vulnerability can be triggered by anyone who can reach the Detail or List plugin, it is easily exploitable in a typical web environment. No EPSS score is available, and the flaw is not yet listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 25, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the femanager extension to the latest released version once a patch is issued.
  • Restrict access to the Detail and List plugins so that only authenticated users can query them.
  • If a patch cannot be applied immediately, uninstall or disable the femanager extension to prevent further data exposure.

Generated by OpenCVE AI on August 25, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Typo3
Typo3 extension "femanager"
Vendors & Products Typo3
Typo3 extension "femanager"

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.
Title Information Disclosure in extension "femanager" (femanager)
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Typo3 Extension "femanager"
cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-08-25T14:51:54.880Z

Reserved: 2026-08-20T13:10:12.063Z

Link: CVE-2026-77135

cve-icon Vulnrichment

Updated: 2026-08-25T14:46:27.211Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T09:17:34.010

Modified: 2026-08-26T17:13:53.420

Link: CVE-2026-77135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:37:45Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key