{"id":"CVE-2026-77142","title":"The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on …","summary":"The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on …","severity":"none","cwe":["CWE-639","CWE-862"],"published":"2026-08-25","updated":"2026-09-28","sourceUpdated":"2026-09-28T23:10:00.143","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77142","references":[{"url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-020","label":"f4fb688c-4412-4426-b4b8-421ecf27b14a"}],"tags":["nvd"],"ingestedAt":"2026-09-28T23:23:00.543Z","slug":"CVE-2026-77142","body":"## Overview\n\nThe frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor who knows the identifier of a company record from the public directory can submit a modified update request for that record directly and overwrite its data, without the application ever confirming that the visitor owns it.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}