PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77144 TYPO3 CVE debrief

CVE-2026-77144 is a high-severity vulnerability in the TYPO3 Extension 'Events 2'. A user with frontend event management access could create an event attributed to another organizer due to insufficient permission checks. This vulnerability allows for potential misattribution of events and increased risk of unauthorized event creation. Defenders responsible for TYPO3 installations with the 'Events 2' extension should assess exposure and implement compensating controls to prevent unauthorized event creation. This includes reviewing permission checks and monitoring for suspicious event creation activity. The CVE record and NVD entry provide details on the vulnerability, including its

Vendor
TYPO3
Product
Extension "Events 2"
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-28
Advisory published
2026-08-25
Advisory updated
2026-09-28

Who should care

Defenders responsible for TYPO3 installations with the 'Events 2' extension should assess exposure and implement compensating controls to prevent unauthorized event creation. This includes reviewing permission checks and monitoring for suspicious event creation activity.

Why it matters

CVE-2026-77144 is a high-severity vulnerability in the TYPO3 Extension 'Events 2' that allows event creation under another organizer's name. Defenders should prioritize verifying exposure and implementing compensating controls to prevent unauthorized event creation and potential misattribution.

  • Potential misattribution of events due to insufficient permission checks.
  • Increased risk of unauthorized event creation by users with frontend event management access.
  • Need for verification of exposure and implementation of compensating controls.

Technical summary

The TYPO3 Extension 'Events 2' has a high-severity vulnerability (CVSS score of 7.1) that allows a user with frontend event management access to create an event attributed to another organizer. This is due to insufficient permission checks, specifically a missing check for the organizer ID in the request. The vulnerability is classified as CWE-915 and has a high CVSS severity score. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and classification. However, additional information on affected versions and remediation is limited.

Defensive priority

Defenders should prioritize verifying exposure and implementing compensating controls, as the vulnerability allows for event creation under another organizer's name, potentially leading to misattribution and confusion.

Recommended defensive actions

  • Verify exposure by checking for frontend event management access and potential misattribution of events.
  • Implement compensating controls to prevent unauthorized event creation.
  • Monitor for suspicious event creation activity.
  • Review and update permission checks for event management.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 7.1 and CWE-915 classification. However, additional information on affected versions and remediation is limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77144 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77144

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77144 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77144

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://typo3.org/security/advisory/typo3-ext-sa-2026-026

    f4fb688c-4412-4426-b4b8-421ecf27b14a

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.