Authorization bypass through user-controlled key in Telephone Directory - CVE-2026-77140
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. A remote attacker can overwrite the record without a valid edit link or any ownership check.