PT-2026-82423 · Joomla · Joomla Event Manager

CVE-2026-77035

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Joomla Event Manager versions prior to 5.0.1
Description A registered user with edit-own rights, specifically those with the eventowner=1 setting or core.edit.own permission, can take over another user's event or venue record. This is achieved by sending a POST request containing another user's record ID along with their own ID in the created by variable.
Recommendations Update Joomla Event Manager to version 5.0.1 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77035

Affected Products

Joomla Event Manager