CVE-2026-77145
Received Received - Intake

Frontend Event Management Permission Bypass in Event Management System

Vulnerability report for CVE-2026-77145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: TYPO3

Description

The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
typo3 events2 to 10.2.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a permission check flaw in the frontend management update flow. The system verified permissions for a different event than the one being modified. A user with frontend event management access could alter events belonging to other organizers without proper authorization.

Detection Guidance

To detect this vulnerability, check if your TYPO3 Events 2 extension is running a vulnerable version (10.2.11 or below). Use the TYPO3 extension manager or run commands like 'composer show typo3/cms-events2' to verify the installed version. If the version is outdated, update it to 10.2.12 or later immediately.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to modify events they do not own, potentially leading to data tampering, misinformation, or disruption of event management operations. Users with legitimate access may face integrity risks.

Compliance Impact

This vulnerability could impact compliance by enabling unauthorized data modifications, violating integrity principles in GDPR and HIPAA. It may lead to unauthorized access to personal or sensitive data, triggering non-compliance penalties under these regulations.

Mitigation Strategies

Review and correct the permission checks for frontend event management to ensure users can only modify events they are authorized to access. Implement strict access controls and audit event modification logs for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart