PT-2026-83839 · Joomla · Helix Ultimate

CVE-2026-78075

·

Published

2026-08-31

·

Updated

2026-08-31

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Helix Ultimate versions prior to 2.2.10
Description Broken Object-Level Authorization occurs in the blog image deletion process. The function Blog::remove image() verifies if a user is authorized to edit the provided article ID but fails to confirm if the specified image path src is actually associated with that article. In Joomla 3 environments where physical file deletion is enabled, an authorized author can provide their own article ID and an arbitrary file path within the /images/ directory to delete unauthorized files.
Recommendations Update Helix Ultimate to version 2.2.10 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78075

Affected Products

Helix Ultimate