Joomla · Joomla! · CVE-2026-71574
**Name of the Vulnerable Software and Affected Versions**
Joomla! Core versions 4.0.0 through 5.4.7
Joomla! Core versions 6.0.0 through 6.1.2
**Description**
An improper access check allows unauthorized users to perform mutation actions in webservice endpoints. This occurs because the Access Control List (ACL) checks are inconsistent, permitting actions via the webservice that are otherwise restricted within the backend user interface.
**Recommendations**
Update Joomla! Core versions 4.0.0 through 5.4.7 to a version newer than 5.4.7.
Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.