Typo3 · Femanager Extension · CVE-2026-77135
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
The user detail view of the extension does not verify if the requested user record matches the configured or logged-in target. This allows visitors with access to the Detail or List plugin to retrieve profile data of other frontend users, such as name, email, date of birth, and address, by providing an arbitrary `user ID`.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.