PT-2026-77194 · Joomla · Joomla!
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Joomla! Core versions 4.0.0 through 5.4.7
Joomla! Core versions 6.0.0 through 6.1.2
Description
Improper Access Control List (ACL) checks in custom fields webservice endpoints allow unauthorized users to create fields for components they should not be able to access.
Recommendations
Update Joomla! Core versions 4.0.0 through 5.4.7 to a version newer than 5.4.7.
Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomla!