Executive brief
The Events 2 TYPO3 extension manages event creation and modification for website organizers. A permission check bug allows users with event management access to modify events belonging to other organizers by exploiting a mismatch between the permission verification and the actual event being modified.
Technical details
This is a broken access control vulnerability (CWE-639, CWE-915) in the TYPO3 Events 2 extension frontend management update flow. The vulnerability occurs because the permission check verifies a different event entity than the one the request modifies. A user with frontend event management access can craft a request to modify an event belonging to a different organizer; the permission validation passes due to the mismatch, allowing the modification to proceed. This requires network access and valid event management credentials. The vulnerability is fixed in versions 8.6.3, 9.4.2, and 10.2.12.
Affected products
- jweiland Events 2 8.6.2 and below, 9.0.0-9.4.1, 10.0.0-10.2.11
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: versions 8.6.3, 9.4.2, and 10.2.12 released