CVE-2026-46721 Details
Description
The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.
A broken access control vulnerability has been identified in the TYPO3 extension 'Frontend User Registration' (sf_register), specifically in versions 14.0.0 to 14.0.1 and 13.2.3 and below. The issue arises because the create and edit flows do not properly restrict user properties or enforce access control on frontend user group assignments. This lack of restriction allows an attacker to assign arbitrary frontend user groups to newly registered or edited accounts, thereby gaining unauthorized access to content and functionalities reserved for privileged frontend user groups.
Users of the 'Frontend User Registration' extension are advised to update to version 14.0.2 or 13.2.4, available through the TYPO3 extension manager, Packagist, or by downloading the ZIP files from the TYPO3 extensions website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-009 | TYPO3 | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | TYPO3 |
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 Frontend User Registration | >= 14.0.0, <= 14.0.1 (semver) <= 13.2.3 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | TYPO3 |
Volerion