SB2026082649 - Authorization bypass through user-controlled key in Forum extension for TYPO3



SB2026082649 - Authorization bypass through user-controlled key in Forum extension for TYPO3

Published: August 26, 2026

Security Bulletin ID SB2026082649
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-77143)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. A remote attacker can submit a modified update request for that topic directly and overwrite its content.


Remediation

Install update from vendor's website.