Description
Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.
Published: 2026-08-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Joomla extension for iCagenda contains an access control bypass that permits a backend operator with only com_icagenda permissions to enumerate all Joomla user profiles. The flaw exposes usernames, email addresses and other profile information, representing an information disclosure vulnerability classified as CWE‑284. The description explicitly confirms that the enumeration ability is available to operators with restricted access, indicating that the privilege escalation leads directly to visibility of user data that should be protected.

Affected Systems

The vulnerability is present in the iCagenda extension for Joomla. Versions up to 4.0.11 appear to be affected, although the CVE description does not specify a lower bound. The vendor is icagenda.com. Any installation of iCagenda that has not been updated to a revision beyond 4.0.11 remains susceptible.

Risk and Exploitability

The CVSS score of 5.1 assigns the issue a medium severity rating, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been identified. Exploitability requires a Joomla backend account that already has com_icagenda scope; the likely attack vector therefore involves either the compromise of such an account or social engineering of a user with sufficient module permissions. If an attacker gains or is lent this access, they can enumerate all site users and collect sensitive data.

Generated by OpenCVE AI on August 14, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the iCagenda extension to the latest available version to eliminate the ACL flaw.
  • If an upgrade cannot be performed immediately, revoke or severely restrict the com_icagenda permission from all backend user groups to prevent enumeration.
  • As a temporary measure, disable the iCagenda component through the Joomla Extensions Manager until a patch is applied.

Generated by OpenCVE AI on August 14, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.icagenda.com/ cve-icon cve-icon
History

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Icagenda.com
Icagenda.com icagenda Extension For Joomla
Vendors & Products Icagenda.com
Icagenda.com icagenda Extension For Joomla

Fri, 14 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.
Title Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Icagenda.com Icagenda Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-18T08:01:05.188Z

Reserved: 2026-08-07T12:50:15.221Z

Link: CVE-2026-71570

cve-icon Vulnrichment

Updated: 2026-08-17T15:38:59.934Z

cve-icon NVD

Status : Deferred

Published: 2026-08-14T21:17:56.807

Modified: 2026-08-26T16:35:20.160

Link: CVE-2026-71570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T23:00:05Z

Weaknesses