SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77144

HIGH · CVSS 7.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows users with frontend event management access to create events that are incorrectly attributed to other organizers, bypassing proper permission checks. This could lead to unauthorized event management and potential misuse of organizer records. Organizations utilizing the affected frontend management plugin should prioritize addressing this issue to prevent unauthorized access and maintain the integrity of event management.

CVE
CVE-2026-77144
Severity
HIGH
CVSS
7.1
EPSS
0.30%

Original NVD Description

The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with frontend event management access could therefore create an event that is attributed to another organizer.