TYPO3 CMS Extension SelfService Priv Escalation via FG Assignment (CVE-2026-77133)
CVE-2026-77133 Published on August 25, 2026
Broken Access Control in extension "femanager" (femanager)
The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.
Vulnerability Analysis
CVE-2026-77133 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-77133 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
TYPO3 Extension "femanager":- Version 13.0.0 and below 13.3.5 is affected.
- Version 8.0.0 and below 8.4.2 is affected.
- Version 7.0.0 and below 7.5.5 is affected.
- Before 6.4.5 is affected.