Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-023 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this issue requires only that disableOverrideDemand is not enabled. | |
| Title | Broken Access Control in extension "Event management and registration" (sf_event_mgt) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:44.929Z
Reserved: 2026-08-20T13:10:12.062Z
Link: CVE-2026-77128
No data.
Status : Received
Published: 2026-08-25T09:17:33.033
Modified: 2026-08-25T09:17:33.033
Link: CVE-2026-77128
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:30:05Z