CVE-2026-77142: TYPO3 Extension Industry Directory
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it.
Affected products
- TYPO3 Extension Industry Directory: from 8.0.0, before 8.1.2 (fixed in 8.1.2); from 7.0.0, before 7.0.3 (fixed in 7.0.3); before 6.1.6 (fixed in 6.1.6)
Published 2026-08-25. Last modified 2026-09-28.