High severityNVD Advisory· Published Aug 25, 2026· Updated Sep 28, 2026
CVE-2026-77146
CVE-2026-77146
Description
The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- TYPO3: 24 Vulnerabilities Disclosed, Including Critical RCE and Code Execution FlawsVypr Intelligence · Aug 25, 2026