CVE-2026-77133: TYPO3 Extension Femanager
Medium severity, CVSS 6.0. EPSS: 0.4% chance of exploitation in the next 30 days.
The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.
Affected products
- TYPO3 Extension Femanager: from 13.0.0, before 13.3.5 (fixed in 13.3.5); from 8.0.0, before 8.4.2 (fixed in 8.4.2); from 7.0.0, before 7.5.5 (fixed in 7.5.5); before 6.4.5 (fixed in 6.4.5)
Published 2026-08-25. Last modified 2026-08-26.