Junglewise Threat Intelligence

CVE-2026-77135: in2code femanager broken access control in user detail view

CVE-2026-77135 · Severity: info · CVSS 7.5 · Published 2026-08-25

Technologies: In2code Femanager. Vendors: In2code.

Executive brief

femanager is a frontend user management extension for TYPO3, a popular open-source CMS. The extension's user detail view fails to properly verify that a requested user record belongs to the logged-in user, allowing attackers to view any other frontend user's private profile information including name, email, date of birth, and address by simply changing a user ID parameter.

Technical details

This is a broken access control vulnerability (CWE-862/863) in the user detail view functionality of the femanager extension. The vulnerable component fails to validate that the requested user ID matches either the configured target user or the currently logged-in user before exposing personal data. An unauthenticated or authenticated attacker with access to the Detail or List plugin can exploit this by supplying an arbitrary user ID in the request, resulting in unauthorized information disclosure of sensitive profile attributes. The vulnerability affects versions 6.4.4 and below, 7.0.0–7.5.4, 8.0.0–8.4.1, and 13.0.0–13.3.4. Patches are available in versions 6.4.5, 7.5.5, 8.4.2, and 13.3.5.

Affected products

  • in2code femanager 6.4.4 and below, 7.0.0–7.5.4, 8.0.0–8.4.1, 13.0.0–13.3.4

Timeline

  • 2026-08-25: disclosed

References

Related threats