Description
The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.
Published: 2026-08-25
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized password reset and account takeover
Action: Immediate Patch
AI Analysis

Impact

The femanager invitation controller does not abort processing after redirecting when supplied with invalid or missing input such as a bad hash or a user that does not exist, is disabled, or has been deleted. An unauthenticated attacker can exploit this flaw to set a new password for, and thereby re‑enable, any existing frontend user account. This effectively provides full ownership of that user’s account, allowing access to any personal data that the user has submitted, as well as potential privilege escalation if the account has higher authorisation than normal frontend users.

Affected Systems

The vulnerability affects the TYPO3 extension femanager, but only the 8.x series of that extension. Versions prior to 8.x or newer releases are not impacted, and the flaw is not present in other TYPO3 extensions.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. EPSS information is not available, but the flaw permits a completely unauthenticated, remote attacker to compromise arbitrary frontend accounts by simply crafting a single HTTP request. Although it is not listed in CISA KEV, the impact on confidentiality, integrity, and availability of user data is substantial, and the exploitation path is straightforward, making mitigation a priority.

Generated by OpenCVE AI on August 25, 2026 at 10:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade femanager to a version newer than 8.x that contains the patched invitation controller
  • If an upgrade is delayed, configure the extension to disable the invitation feature or block the password reset endpoints for unauthenticated users
  • Monitor incoming POST requests to the invitation endpoint for abnormal activity and block offending IPs

Generated by OpenCVE AI on August 25, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Typo3
Typo3 extension "femanager"
Vendors & Products Typo3
Typo3 extension "femanager"

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.
Title Broken Access Control in extension "femanager" (femanager)
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Typo3 Extension "femanager"
cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-08-25T14:51:55.066Z

Reserved: 2026-08-20T13:10:15.962Z

Link: CVE-2026-77146

cve-icon Vulnrichment

Updated: 2026-08-25T14:46:29.296Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T09:17:35.820

Modified: 2026-08-26T17:13:53.420

Link: CVE-2026-77146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:38:00Z

Weaknesses