Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-77135 – Information Disclosure (IDOR) – TYPO3 femanager Extension < 6.4.5 / 7.5.5 / 8.4.2 /

Be the first to know when new zero-days emerge:

Summary

CVE-2026-77135 is a high-severity authorization bypass (Insecure Direct Object Reference / missing authorization check) in the "femanager" extension for TYPO3 CMS. The extension’s frontend user detail view does not verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user’s personal profile data simply by supplying an arbitrary user ID. The issue carries a CVSS score of 8.2 (High) and is remotely exploitable over the network with no authentication or user interaction required.

Technical details

  • Root cause: The femanager Detail/List plugin’s controller logic fails to check whether the requested frontend user record actually belongs to the currently logged-in user or matches the plugin’s configured target before rendering the record.
  • Trigger conditions: A page containing the femanager Detail or List plugin must be publicly reachable; the attacker supplies an arbitrary frontend user ID (e.g., via a URL/GET parameter) to the detail view.
  • Attack vector: Network-based, low attack complexity, no privileges or user interaction required (per the associated CVSS v4.0 vector).
  • Impact: Disclosure of another frontend user’s personally identifiable information, including name, email address, date of birth, and physical address — without needing valid credentials for that account.

Affected software

  • TYPO3 extension femanager (in2code/femanager), versions:
    • 6.4.4 and earlier
    • 7.0.0 – 7.5.4
    • 8.0.0 – 8.4.1
    • 13.0.0 – 13.3.4

Severity

  • CVSS Score: 8.2 (High)
  • CVSS v4.0 Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  • No CVSS v3.1 vector has been published for this specific CVE by the vendor at the time of writing.

Mitigation and recommended actions

  • Immediate: Upgrade the femanager extension to the patched release for your branch:
    • 6.x → 6.4.5
    • 7.x → 7.5.5
    • 8.x → 8.4.2
    • 13.x → 13.3.5
  • If patching is not immediately possible:
    • Restrict or disable public access to pages using the femanager Detail and List plugins until the update can be applied.
    • Monitor frontend access logs for anomalous, sequential, or scripted requests to detail-view URLs with varying user ID parameters.
    • Limit exposure of sensitive frontend user fields (email, date of birth, address) in templates rendered by the affected plugins as a defense-in-depth measure.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge