CVE-2026-77128
Received Received - Intake

Unauthenticated Event Access in Repository Extension

Vulnerability report for CVE-2026-77128, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: TYPO3

Description

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
typo3 sf_event_mgt to 5.9.3 (exc)
typo3 sf_event_mgt From 6.0.0 (inc) to 6.7.1 (inc)
typo3 sf_event_mgt From 7.0.0 (inc) to 7.9.2 (inc)
typo3 sf_event_mgt From 8.0.0 (inc) to 8.6.1 (inc)
typo3 sf_event_mgt From 9.0.0 (inc) to 9.0.2 (inc)
typo3 sf_event_mgt 5.9.3
typo3 sf_event_mgt 6.7.2
typo3 sf_event_mgt 7.9.3
typo3 sf_event_mgt 8.6.2
typo3 sf_event_mgt 9.0.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77128 is a Broken Access Control vulnerability in the TYPO3 extension 'Event management and registration' (sf_event_mgt). It allows unauthenticated remote users to bypass access restrictions by passing a demand-override parameter to view hidden or time-restricted events. Exploitation is only possible if the disableOverrideDemand plugin setting is not enabled.

Detection Guidance

Check if the 'disableOverrideDemand' setting is enabled in the sf_event_mgt extension configuration. Review access logs for unusual repository query parameter manipulations or unauthorized event views.

Impact Analysis

An attacker could access sensitive event data that should be restricted, such as private or future events. This could lead to unauthorized disclosure of information, potential data leaks, or misuse of event details if the extension is used for sensitive purposes.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR principles of data protection and privacy. For HIPAA, if the extension handles protected health information, unauthorized access could result in compliance breaches and potential penalties.

Mitigation Strategies

Update the sf_event_mgt extension to the latest patched version (5.9.3, 6.7.2, 7.9.3, 8.6.2, or 9.0.3). Ensure the 'disableOverrideDemand' setting is enabled to prevent parameter manipulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77128. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart