PT-2026-83840 · Joomla · Helix Ultimate
CVE-2026-78076
·
Published
2026-08-31
·
Updated
2026-08-31
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Helix Ultimate versions prior to 2.2.10
Description
Broken access control and missing authorization exist in the MegaMenu settings. The AJAX endpoint 'save-megamenu-settings' does not enforce item-level and menu-level edit permissions, specifically
core.edit on com menus.item.{id} or core.admin. This allows an authenticated user to submit modified layout parameters for arbitrary menu items without proper authorization.Recommendations
Update Helix Ultimate to version 2.2.10 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helix Ultimate