PT-2026-97516 · Joomla · Easy Store

CVE-2026-90904

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Easy Store versions 1.0.0 through 3.0.0
Description Broken Access Control (ACL Bypass) exists in the ApiController record editing functionality. The allowEdit() function in ApiController.php contains a hardcoded return value of true, which bypasses Joomla component-level and asset-level Access Control List (ACL) permission checks. This allows any authenticated backend user to edit any EasyStore record, regardless of their assigned permissions.
Recommendations Update Easy Store to a version where the allowEdit() function is updated to use proper ACL authorization checks via AccessControl::create()->canEdit() instead of a hardcoded boolean.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90904

Affected Products

Easy Store