Junglewise Threat Intelligence

CVE-2026-77145: TYPO3 Events 2 broken access control in update flow

CVE-2026-77145 · Severity: info · Published 2026-08-25

Executive brief

The Events 2 TYPO3 extension manages event creation and modification for website organizers. A permission check bug allows users with event management access to modify events belonging to other organizers by exploiting a mismatch between the permission verification and the actual event being modified.

Technical details

This is a broken access control vulnerability (CWE-639, CWE-915) in the TYPO3 Events 2 extension frontend management update flow. The vulnerability occurs because the permission check verifies a different event entity than the one the request modifies. A user with frontend event management access can craft a request to modify an event belonging to a different organizer; the permission validation passes due to the mismatch, allowing the modification to proceed. This requires network access and valid event management credentials. The vulnerability is fixed in versions 8.6.3, 9.4.2, and 10.2.12.

Affected products

  • jweiland Events 2 8.6.2 and below, 9.0.0-9.4.1, 10.0.0-10.2.11

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: versions 8.6.3, 9.4.2, and 10.2.12 released

References

Related threats