TYPO3 Ext: Admin Token Omitted Allows User Self-Approval via Confirmation Hash
CVE-2026-77134 Published on August 25, 2026
Broken Access Control in extension "femanager" (femanager)
The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting admin approval.
Vulnerability Analysis
CVE-2026-77134 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-77134 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
TYPO3 Extension "femanager":- Version 13.0.0 and below 13.3.5 is affected.
- Version 8.0.0 and below 8.4.2 is affected.
- Version 7.0.0 and below 7.5.5 is affected.
- Before 6.4.5 is affected.