SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77134

HIGH · CVSS 8.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows regular users to bypass the admin approval process by using a confirmation hash that can be obtained through a public action, effectively enabling unauthorized account activation. This could lead to unauthorized access and potential exploitation of user accounts. Organizations utilizing this extension should prioritize remediation to prevent potential account takeover and unauthorized access incidents.

CVE
CVE-2026-77134
Severity
HIGH
CVSS
8.3
EPSS
0.24%

Original NVD Description

The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting admin approval.