CVE-2026-77135
Received Received - Intake

Information Disclosure in TYPO3 Frontend User Extension

Vulnerability report for CVE-2026-77135, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: TYPO3

Description

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and address, by supplying an arbitrary user ID.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
in2code femanager to 6.4.5 (exc)
in2code femanager From 7.0.0 (inc) to 7.5.4 (inc)
in2code femanager From 8.0.0 (inc) to 8.4.1 (inc)
in2code femanager From 13.0.0 (inc) to 13.3.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Information Disclosure issue in the femanager extension for TYPO3. It allows any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data by supplying an arbitrary user ID. The extension fails to verify if the requested user record matches the logged-in user or configured target, exposing sensitive data like name, email, date of birth, and address.

Detection Guidance

Check if the femanager extension is installed and its version is below the patched versions (6.4.5, 7.5.5, 8.4.2, or 13.3.5). Inspect network traffic for requests to Detail or List plugin endpoints that include arbitrary user IDs.

Impact Analysis

This vulnerability can lead to unauthorized access to sensitive user data, including personal information such as names, emails, dates of birth, and addresses. Attackers could exploit it to gather private details about users without their consent, potentially leading to identity theft, privacy violations, or further targeted attacks.

Compliance Impact

This vulnerability likely violates data protection regulations such as GDPR and HIPAA by exposing personal user data without authorization. GDPR requires strict controls to protect personal data, while HIPAA mandates safeguards for protected health information. A breach like this could result in legal penalties, fines, and reputational damage due to non-compliance.

Mitigation Strategies

Update the femanager extension to the latest patched version (6.4.5, 7.5.5, 8.4.2, or 13.3.5) immediately. If updating is not possible, disable the Detail and List plugins or restrict access to them.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77135. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart