High severityNVD Advisory· Published Aug 25, 2026· Updated Aug 26, 2026
CVE-2026-77134
CVE-2026-77134
Description
The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting admin approval.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- TYPO3: 24 Vulnerabilities Disclosed, Including Critical RCE and Code Execution FlawsVypr Intelligence · Aug 25, 2026