PT-2026-72116 · Joomla · Icagenda.Com
CVE-2026-71570
·
Published
2026-08-14
·
Updated
2026-08-17
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
icagenda.com versions prior to 2.0.0 and 4.0.11
Description
An Access Control List (ACL) bypass exists where a backend operator with access restricted to the
com icagenda component can enumerate Joomla user profiles. ACL is a mechanism used to define permissions for users or systems to access specific resources.Recommendations
Update icagenda.com to version 2.0.0 or later.
Update icagenda.com to version 4.0.11 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icagenda.Com