Description
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
Published: 2026-07-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helix Ultimate extension for Joomla is vulnerable to unauthenticated arbitrary file deletion. The flaw allows any user to delete existing files without authentication, which is an improper authorization (CWE‑862). It is inferred that the removal of critical files could lead to content loss, site defacement, or denial‑of‑service at the application level.

Affected Systems

Versions of Helix Ultimate earlier than 2.2.7 are affected. The extension is into Joomla CMS installations. Upgrading to vulnerability; older deployments remain susceptible.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while an EPSS score below 1% suggests exploitation is unlikely but not impossible. The bug is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request access are required. It is inferred that an attacker who can reach the site may specify arbitrary file paths to delete, presenting a significant risk to sensitive content.

Generated by OpenCVE AI on July 31, 2026 at 12:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Helix Ultimate extension to version 2.2.7 or later, which removes the unauthenticated delete functionality.
  • If an update is unavailable, disable the file deletion feature in the extension or remove the extension entirely from the Joomla installation.
  • Implement web application firewall rules to block HTTP requests that attempt to invoke deletion operations or to restrict the file‑deletion endpoints to authenticated users only.

Generated by OpenCVE AI on July 31, 2026 at 12:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Wed, 15 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion < 2.2.7 Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
Title Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion < 2.2.7
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:57:30.551Z

Reserved: 2026-06-25T16:55:04.094Z

Link: CVE-2026-57830

cve-icon Vulnrichment

Updated: 2026-07-14T14:16:32.973Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses