{"id":"GHSA-v348-vr4q-fv9p","summary":"TYPO3 sf_register extension allows unauthorized assignment of frontend user groups","details":"The `create` and `edit` flows in the TYPO3 extension sf_register do not restrict which user properties may be submitted, and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to content and functionality restricted to privileged frontend user groups.","aliases":["CVE-2026-46721"],"modified":"2026-09-10T03:50:47.699684210Z","published":"2026-05-19T12:31:39Z","database_specific":{"cwe_ids":["CWE-639"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-29T22:58:05Z","nvd_published_at":"2026-05-19T10:16:24Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46721"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/evoweb/sf-register/CVE-2026-46721.yaml"},{"type":"PACKAGE","url":"https://github.com/evoWeb/sf_register"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-009"}],"affected":[{"package":{"name":"evoweb/sf-register","ecosystem":"Packagist","purl":"pkg:composer/evoweb/sf-register"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0"},{"fixed":"14.0.2"}]}],"versions":["14.0.0","14.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-v348-vr4q-fv9p/GHSA-v348-vr4q-fv9p.json"}},{"package":{"name":"evoweb/sf-register","ecosystem":"Packagist","purl":"pkg:composer/evoweb/sf-register"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"13.2.4"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.1.0","10.1.1","10.1.2","10.1.3","10.1.4","10.1.5","10.1.6","10.1.7","10.2.0","11.0.0","11.1.0","11.1.1","11.1.2","11.1.3","11.1.4","11.1.5","12.0.0","12.0.1","13.0.0","13.0.1","13.1.0","13.1.1","13.1.2","13.1.3","13.1.4","13.2.0","13.2.1","13.2.2","13.2.3","6.2.9","8.7.0","8.7.1","8.7.2","8.7.3","8.8.0","8.8.1","8.8.2","8.8.3","8.8.4","8.8.5","8.8.6","9.0.0","9.1.0","9.2.0","9.3.0","9.4.0","9.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-v348-vr4q-fv9p/GHSA-v348-vr4q-fv9p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}