CVE-2026-46721 PUBLISHED

Broken Access Control in extension "Frontend User Registration" (sf_register)

Assigner: TYPO3
Reserved: 16.05.2026 Published: 19.05.2026 Updated: 19.05.2026

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor TYPO3
Product Extension "Frontend User Registration"
Versions Default: unaffected
  • affected from 14.0.0 to 14.0.2 (excl.)
  • affected from 0 to 13.2.4 (excl.)

Credits

  • Seungbin Yang reporter
  • Sebastian Fischer remediation developer

References

Problem Types

  • CWE-915 CWE
  • CWE-639 CWE