« Volver al listado

CVE-2026-77145

Estado: AplazadaAlta (7.1)—

The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:L sin UI:R indica acceso remoto autenticado. CWE-639 (autorización insuficiente) permite modificar eventos ajenos. Impactos: manipulación de datos (eventos) e inyección en cuentas asociadas.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-77145",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-77145",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-25T14:02:23.965375Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f4fb688c-4412-4426-b4b8-421ecf27b14a",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f4fb688c-4412-4426-b4b8-421ecf27b14a",
      "affectedData": [
        {
          "vendor": "TYPO3",
          "product": "Extension \"Events 2\"",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.0",
              "lessThan": "10.2.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "9.0.0",
              "lessThan": "9.4.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "8.6.3",
              "versionType": "semver"
            }
          ],
          "packageName": "jweiland/events2",
          "collectionURL": "https://packagist.org/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-25T09:17:35.667",
  "references": [
    {
      "url": "https://typo3.org/security/advisory/typo3-ext-sa-2026-026",
      "source": "f4fb688c-4412-4426-b4b8-421ecf27b14a"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f4fb688c-4412-4426-b4b8-421ecf27b14a",
      "description": [
        {
          "lang": "en",
          "value": "CWE-639"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers."
    },
    {
      "lang": "es",
      "value": "La verificación de permisos para el flujo de actualización de la gestión del frontend verificó un evento diferente al que la solicitud procedió a modificar. Un usuario con acceso a la gestión de eventos del frontend, por lo tanto, podría modificar eventos pertenecientes a otros organizadores."
    }
  ],
  "lastModified": "2026-09-28T23:10:00.143",
  "sourceIdentifier": "f4fb688c-4412-4426-b4b8-421ecf27b14a"
}