Impact
Improper access control allows users who are unauthorized in the backend UI to perform mutation actions on webservice endpoints, enabling them to create, edit, or delete site content and potentially alter configuration. This is an Access Control weakness (CWE-284) that can lead to integrity violations and unauthorized data exposure.
Affected Systems
The Joomla! CMS is affected in all releases from Joomla 4.0.0 through 5.4.7 and from Joomla 6.0.0 through 6.1.2. Operators running any of these versions should verify their installation and apply the pending fix immediately.
Risk and Exploitability
The vulnerability has a CVSS score of 8.5 and is not listed in the CISA KEV catalog; its EPSS score is currently not available, leaving the exploitation probability unknown. The affected webservice endpoints are exposed over the network, making the attack likely remote and accessible to unauthenticated or low‑privileged users. While no public exploit is documented, the severity indicates a high likelihood that attackers will attempt exploitation once the issue is discovered.
OpenCVE Enrichment