Executive brief
The femanager extension for TYPO3 fails to properly validate admin approval requests for new user accounts. An attacker can obtain a standard user confirmation token through a public action and use it to self-approve their own account even when admin approval is required, bypassing the intended account creation workflow and gaining unauthorized access.
Technical details
The vulnerability is a broken access control flaw (CWE-862, CWE-863) in the femanager extension's admin-approval request processing. The extension accepts a standard user confirmation hash—obtainable by any unauthenticated visitor through the public resend-confirmation action—as sufficient authorization to approve a pending user account, instead of requiring a dedicated admin confirmation token. An attacker can leverage this to self-approve their account without legitimate admin authorization, resulting in unauthorized account activation and potential privilege escalation. Network reachable; no authentication required. Patches available in versions 6.4.5, 7.5.5, 8.4.2, and 13.3.5.
Affected products
- in2code femanager 6.4.4 and below, 7.0.0-7.5.4, 8.0.0-8.4.1, 13.0.0-13.3.4
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixes available in versions 6.4.5, 7.5.5, 8.4.2, 13.3.5