The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-009 |
|
History
Tue, 19 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups. | |
| Title | Broken Access Control in extension "Frontend User Registration" (sf_register) | |
| Weaknesses | CWE-639 CWE-915 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-05-19T09:19:10.688Z
Reserved: 2026-05-16T09:55:27.478Z
Link: CVE-2026-46721
No data.
Status : Received
Published: 2026-05-19T10:16:24.853
Modified: 2026-05-19T10:16:24.853
Link: CVE-2026-46721
No data.
OpenCVE Enrichment
Updated: 2026-05-19T11:30:03Z