CVE-2026-77145: Broken Access Control in extension "Events 2" (events2)
Published Aug 25, 2026
·Updated
The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.
Event History
Aug 25, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness