Joomla · Joomla! · CVE-2026-72532
**Name of the Vulnerable Software and Affected Versions**
Joomla! Core versions 4.0.0 through 5.4.7
Joomla! Core versions 6.0.0 through 6.1.2
**Description**
Improper Access Control List (ACL) checks in category webservice endpoints allow unauthorized users to create categories. ACL is a mechanism used to manage permissions and restrict access to specific resources within a system.
**Recommendations**
Update Joomla! Core versions 4.0.0 through 5.4.7 to a version newer than 5.4.7.
Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.