CVE-2026-77146: TYPO3 Extension Femanager

High severity, CVSS 8.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.

Affected products

  • TYPO3 Extension Femanager: from 8.0.0, before 8.4.2 (fixed in 8.4.2)

Published 2026-08-25. Last modified 2026-09-28.