The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-026 |
|
History
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers. | |
| Title | Broken Access Control in extension "Events 2" (events2) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:32.558Z
Reserved: 2026-08-20T13:10:15.962Z
Link: CVE-2026-77145
No data.
Status : Received
Published: 2026-08-25T09:17:35.667
Modified: 2026-08-25T09:17:35.667
Link: CVE-2026-77145
No data.
OpenCVE Enrichment
Updated: 2026-08-25T11:45:03Z
Weaknesses