Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v348-vr4q-fv9p | TYPO3 sf_register extension allows unauthorized assignment of frontend user groups |
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-009 |
|
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 extension "frontend User Registration" |
|
| Vendors & Products |
Typo3
Typo3 extension "frontend User Registration" |
Tue, 19 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups. | |
| Title | Broken Access Control in extension "Frontend User Registration" (sf_register) | |
| Weaknesses | CWE-639 CWE-915 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-05-19T13:21:39.704Z
Reserved: 2026-05-16T09:55:27.478Z
Link: CVE-2026-46721
Updated: 2026-05-19T13:21:32.290Z
Status : Deferred
Published: 2026-05-19T10:16:24.853
Modified: 2026-06-17T10:53:51.843
Link: CVE-2026-46721
No data.
OpenCVE Enrichment
Updated: 2026-05-20T10:39:39Z
Github GHSA