TYPO3 CMS: Frontend Event Management Permission Bypass Allows Tampering
CVE-2026-77145 Published on August 25, 2026
Broken Access Control in extension "Events 2" (events2)
The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.
Vulnerability Analysis
CVE-2026-77145 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an Insecure Direct Object Reference / IDOR Vulnerability?
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVE-2026-77145 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.
Affected Versions
TYPO3 Extension "Events 2":- Version 10.0.0 and below 10.2.12 is affected.
- Version 9.0.0 and below 9.4.2 is affected.
- Before 8.6.3 is affected.