SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77146

HIGH · CVSS 8.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to reset passwords and re-enable arbitrary frontend user accounts due to improper handling of invalid input in the invitation controller of the affected extension. This poses a significant security risk, as it can lead to unauthorized access to user accounts. Organizations using version 8.x of the extension should prioritize remediation to mitigate potential account takeovers.

CVE
CVE-2026-77146
Severity
HIGH
CVSS
8.3
EPSS
0.25%

Original NVD Description

The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.