PT-2026-77193 · Joomla · Joomla!

·

CVE-2026-71574

·

Published

2026-08-18

·

Updated

2026-09-04

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Joomla! Core versions 4.0.0 through 5.4.7 Joomla! Core versions 6.0.0 through 6.1.2
Description An improper access check allows unauthorized users to perform mutation actions in webservice endpoints. This occurs because the Access Control List (ACL) checks are inconsistent, permitting actions via the webservice that are otherwise restricted within the backend user interface.
Recommendations Update Joomla! Core versions 4.0.0 through 5.4.7 to a version newer than 5.4.7. Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2026-71574
CVE-2026-71574

Affected Products

Joomla!