CVE-2026-77134: TYPO3 Extension Femanager
High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting admin approval.
Affected products
- TYPO3 Extension Femanager: from 13.0.0, before 13.3.5 (fixed in 13.3.5); from 8.0.0, before 8.4.2 (fixed in 8.4.2); from 7.0.0, before 7.5.5 (fixed in 7.5.5); before 6.4.5 (fixed in 6.4.5)
Published 2026-08-25. Last modified 2026-08-26.