TYPO3 Ext User Detail View: Arbitrary User Data Disclosure
CVE-2026-77135 Published on August 25, 2026

Information Disclosure in extension "femanager" (femanager)
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-77135 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

What is an Insecure Direct Object Reference / IDOR Vulnerability?

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

CVE-2026-77135 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.


Affected Versions

TYPO3 Extension "femanager":