CVE-2026-77145: TYPO3 Extension Events 2

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.

Affected products

  • TYPO3 Extension Events 2: from 10.0.0, before 10.2.12 (fixed in 10.2.12); from 9.0.0, before 9.4.2 (fixed in 9.4.2); before 8.6.3 (fixed in 8.6.3)

Published 2026-08-25. Last modified 2026-09-28.