NONE · 0

CVE-2026-77140

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UI...

Vulnerability Description

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update action and overwrite that record without a valid edit link or any ownership check.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-77140?

CVE-2026-77140 is a documented vulnerability. The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UI...

How severe is CVE-2026-77140?

CVSS scoring is not yet available for CVE-2026-77140. Check NVD for updates.

Is there a patch for CVE-2026-77140?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.