Description
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.
Published: 2026-08-25
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The femanager extension for TYPO3 does not verify that the requested user record matches the configured or logged‑in target. An attacker with access to the Detail or List plugin can supply any user ID to retrieve that user's name, email, date of birth, and address. The vulnerability allows confidential personal data to be disclosed to unauthenticated or low‑privileged visitors, constituting a high‑severity information‑exposure flaw (CWE‑639).

Affected Systems

Any installation of the femanager extension for TYPO3 is potentially affected. No specific version numbers are listed in the advisory, so the issue likely applies to all current releases until a patch is released.

Risk and Exploitability

The CVSS score of 8.2 indicates a high impact with no authentication required and a network attack vector. Because the vulnerability can be triggered by anyone who can reach the Detail or List plugin, it is easily exploitable in a typical web environment. No EPSS score is available, and the flaw is not yet listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 25, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the femanager extension to the latest released version once a patch is issued.
  • Restrict access to the Detail and List plugins so that only authenticated users can query them.
  • If a patch cannot be applied immediately, uninstall or disable the femanager extension to prevent further data exposure.

Generated by OpenCVE AI on August 25, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.
Title Information Disclosure in extension "femanager" (femanager)
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-08-25T09:00:40.231Z

Reserved: 2026-08-20T13:10:12.063Z

Link: CVE-2026-77135

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T09:17:34.010

Modified: 2026-08-25T09:17:34.010

Link: CVE-2026-77135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T10:30:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key