TYPO3 CMS: Unauthenticated Remote Access via Missing Enable-Field Enforcement
CVE-2026-77128 Published on August 25, 2026
Broken Access Control in extension "Event management and registration" (sf_event_mgt)
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.
Vulnerability Analysis
CVE-2026-77128 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-77128 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
TYPO3 Extension "Event management and registration":- Version 9.0.0 and below 9.0.3 is affected.
- Version 8.0.0 and below 8.6.2 is affected.
- Version 7.0.0 and below 7.9.3 is affected.
- Version 6.0.0 and below 6.7.2 is affected.
- Before 5.9.3 is affected.