Description
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control allows users who are unauthorized in the backend UI to perform mutation actions on webservice endpoints, enabling them to create, edit, or delete site content and potentially alter configuration. This is an Access Control weakness (CWE-284) that can lead to integrity violations and unauthorized data exposure.

Affected Systems

The Joomla! CMS is affected in all releases from Joomla 4.0.0 through 5.4.7 and from Joomla 6.0.0 through 6.1.2. Operators running any of these versions should verify their installation and apply the pending fix immediately.

Risk and Exploitability

The vulnerability has a CVSS score of 8.5 and is not listed in the CISA KEV catalog; its EPSS score is currently not available, leaving the exploitation probability unknown. The affected webservice endpoints are exposed over the network, making the attack likely remote and accessible to unauthenticated or low‑privileged users. While no public exploit is documented, the severity indicates a high likelihood that attackers will attempt exploitation once the issue is discovered.

Generated by OpenCVE AI on August 18, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Joomla! CMS to a version newer than 5.4.7 or 6.1.2 that contains the ACL fix.
  • If an update is not yet possible, block or restrict unauthenticated access to the affected webservice endpoints using firewall rules or .htaccess restrictions, allowing only trusted IP ranges.
  • Review and tighten Joomla ACL configuration to ensure that mutation operations via the API require the same administrative privileges that the backend UI enforces, preventing privilege escalation.

Generated by OpenCVE AI on August 18, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla joomla\!
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla joomla\!
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 17:30:00 +0000


Tue, 18 Aug 2026 16:30:00 +0000


Tue, 18 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Title Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-21T08:59:30.380Z

Reserved: 2026-08-07T13:04:49.114Z

Link: CVE-2026-71574

cve-icon Vulnrichment

Updated: 2026-08-18T19:01:51.957Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T16:18:16.457

Modified: 2026-09-03T15:07:57.073

Link: CVE-2026-71574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:34Z

Weaknesses