CVE-2026-77142: CWE-862 Missing Authorization in TYPO3 Extension "Industry Directory"
Description
CVE-2026-77142 is a high-severity vulnerability in the TYPO3 Extension "Industry Directory" that allows unauthorized modification of company records. The frontend editing feature hides the edit form for companies a visitor does not own using a template-level visibility flag, but the server-side write operation does not verify ownership. This flaw enables an attacker who knows a company record identifier to submit update requests and overwrite data without authorization checks.
CVSS v4.0
Score 8.8high
Affected software
TYPO3
Extension "Industry Directory"
pkg:composer/jweiland/yellowpages2Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The TYPO3 Extension "Industry Directory" contains a missing authorization vulnerability (CWE-862) where the server-side write operation fails to confirm ownership of company records before processing updates. Although the frontend interface hides edit forms for unauthorized users, the backend does not enforce this restriction, allowing unauthorized visitors to modify records by submitting crafted update requests with known identifiers. This vulnerability affects versions 7.0.0, 8.0.0, and all versions prior to 8.1.2. The CVSS 4.0 score is 8.8, indicating high severity with network attack vector, no privileges required, no user interaction, and high impact on integrity.
Potential Impact
An attacker can overwrite company record data in the public directory without owning the record, potentially leading to data tampering and misinformation. This compromises data integrity and trustworthiness of the directory content. There is no indication of confidentiality or availability impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the Industry Directory extension or implement additional server-side authorization checks to verify ownership before processing update requests.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TYPO3
- Date Reserved
- 2026-08-20T13:10:15.962Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8d5b66acd9273b49f365cf
Added to database: 08/25/2026, 09:07:50 UTC
Last enriched: 09/10/2026, 06:37:12 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.