Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-018 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check. | |
| Title | Broken Access Control in extension "Telephone Directory" (telephonedirectory) | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:36.477Z
Reserved: 2026-08-20T13:10:15.962Z
Link: CVE-2026-77140
No data.
Status : Received
Published: 2026-08-25T09:17:34.807
Modified: 2026-08-25T09:17:34.807
Link: CVE-2026-77140
No data.
OpenCVE Enrichment
Updated: 2026-08-25T11:15:04Z