CVE-2026-77146: TYPO3 Extension Femanager
High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.
Affected products
- TYPO3 Extension Femanager: from 8.0.0, before 8.4.2 (fixed in 8.4.2)
Published 2026-08-25. Last modified 2026-09-28.