SB2026082649 - Authorization bypass through user-controlled key in Forum extension for TYPO3
Published: August 26, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-77143)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. A remote attacker can submit a modified update request for that topic directly and overwrite its content.
Remediation
Install update from vendor's website.