TYPO3 Ext User Detail View: Arbitrary User Data Disclosure
CVE-2026-77135 Published on August 25, 2026
Information Disclosure in extension "femanager" (femanager)
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.
Vulnerability Analysis
CVE-2026-77135 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an Insecure Direct Object Reference / IDOR Vulnerability?
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVE-2026-77135 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.
Affected Versions
TYPO3 Extension "femanager":- Version 13.0.0 and below 13.3.5 is affected.
- Version 8.0.0 and below 8.4.2 is affected.
- Version 7.0.0 and below 7.5.5 is affected.
- Before 6.4.5 is affected.