Beveiligingsadvies

CVE-2026-77133

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-25 09:00:41
Laatst bijgewerkt 2026-08-25 14:51:54
Toegewezen door TYPO3
CVSS-score 6.0
Status PUBLISHED

Beschrijving

The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.