TYPO3 Frontend User Group Assignment Bypass (CVE-2026-46721)
CVE-2026-46721 Published on May 19, 2026

Broken Access Control in extension "Frontend User Registration" (sf_register)
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.

Vendor Advisory NVD

Weakness Types

What is a Mass Assignment Vulnerability?

The software receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

CVE-2026-46721 has been classified to as a Mass Assignment vulnerability or weakness.

What is an Insecure Direct Object Reference / IDOR Vulnerability?

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

CVE-2026-46721 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.


Affected Versions

TYPO3 Extension "Frontend User Registration":

Exploit Probability

EPSS
0.07%
Percentile
21.45%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.