Femanager · Femanager · CVE-2026-77146
**Name of the Vulnerable Software and Affected Versions**
femanager versions 8.x
**Description**
The invitation controller fails to stop processing after redirecting when it encounters invalid input, such as a missing hash or users that are non-existent, disabled, or deleted. This allows an unauthenticated attacker to re-enable and set a new password for any existing frontend user account.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.