Description
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.
Published: 2026-07-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomdle component for Joomla includes a default configuration that allows read access to CMS user accounts and the ability to reset their passwords. This flaw falls under insecure default settings and information exposure. An attacker who can reach the extension’s configuration can view user credentials and change passwords, enabling impersonation and further compromise of site integrity.

Affected Systems

The vulnerability affects the Joomdle extension for Joomla, versions earlier than 3.1.1. Users of these versions with the default settings are at risk; no other products are listed.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% suggests low likelihood of widespread exploitation at this time. The flaw is not listed in the CISA KEV catalog. Attackers would likely exploit the web interface or configuration files of the extension, and may need only minimal or no prior authentication to reset passwords or read account data. This attack vector and authentication assumption are inferred from the description. The combination of a high severity rating and low exploitation probability places the risk in a moderate to high category for affected installations.

Generated by OpenCVE AI on August 3, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Joomdle extension to version 3.1.1 or later, which removes the insecure default configuration.
  • If an update cannot be performed immediately, manually change the extension’s settings to disable read access to user accounts and disable the ability for users to reset passwords without proper authorization.
  • Review all installed Joomla extensions for insecure default configurations and apply any vendor‑provided fixes or secure configuration recommendations to prevent similar issues.

Generated by OpenCVE AI on August 3, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.joomdle.com/ cve-icon cve-icon
History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomdle.com
Joomdle.com joomdle Component For Joomla
Vendors & Products Joomdle.com
Joomdle.com joomdle Component For Joomla

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.
Title Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
Weaknesses CWE-1188
CWE-200
References

Subscriptions

Joomdle.com Joomdle Component For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-29T05:41:34.671Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65881

cve-icon Vulnrichment

Updated: 2026-07-28T19:22:49.912Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T13:19:06.207

Modified: 2026-07-28T20:17:27.910

Link: CVE-2026-65881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:15:04Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor