6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.
Basic Information
ID
CVE-2026-46721
Source
TYPO3
Published
May 19, 2026 at 09:19
Affected Product
Vendor
TYPO3
Product
Extension "Frontend User Registration"
Version
14.0.0
Affected Versions
TYPO3 Extension "Frontend User Registration" 14.0.0
TYPO3 Extension "Frontend User Registration" 0
TYPO3 Extension "Frontend User Registration" 0