CVE-2026-77144 HIGH

CVE-2026-77144: Broken Access Control in extension "Events 2" (events2)

Vendor Typo3
Product Extension "Events 2"
Weakness CWE-915
Published August 25, 2026
Last update August 27, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with frontend event management access could therefore create an event that is attributed to another organizer.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 27, 2026 Record updated