Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4241 articles · 196928 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-77143PATCHED
typo3 · extension "forum"

Broken Access Control in extension "Forum" (pforum)

Description

The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update request for that topic directly and overwrite its content, without the application confirming ownership. Topic identifiers are visible in the public forum listing, and exploitation requires no privileged access or non-default configuration.

Affected Products

VendorProductVersions
typo3extension "forum"0

References

  • https://typo3.org/security/advisory/typo3-ext-sa-2026-021(vendor-advisory)

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-77143 | TYPO3 Forum up to 6.2.3 Topic Editing privileges management
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
6.2.4
CWECWE-862, CWE-639
PublishedAug 25, 2026
Trending Score29
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77136EXPKEV
Server-Side Template Injection in extension "powermail" (powermail)
Trending: 92
NONECVE-2026-77138
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
Trending: 34
NONECVE-2026-77141
Broken Access Control in extension "Club Directory" (clubdirectory)
Trending: 29
NONECVE-2026-77142
Broken Access Control in extension "Industry Directory" (yellowpages2)
Trending: 29
NONECVE-2026-77140
Broken Access Control in extension "Telephone Directory" (telephonedirectory)
Trending: 29

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 25, 2026