The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.
{
"cna_assigner": "TYPO3",
"cwe_ids": [
"CWE-639",
"CWE-915"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46721.json"
}{
"extracted_events": [
{
"introduced": "14.0.0"
},
{
"fixed": "14.0.2"
},
{
"introduced": "0"
},
{
"fixed": "13.2.4"
}
],
"source": "AFFECTED_FIELD"
}