Description
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
Published: 2026-08-18
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control checks in Joomla webservice endpoints allow an unauthenticated or privileged user to create custom fields for components they should not manage. This flaw, classified as CWE‑284, can lead to unauthorized data exposure, data integrity violations, and potential misuse of component functionality by attackers. The attacker can inject fields that may store malicious content or be used to manipulate component behavior, impacting the confidentiality and integrity of site data.

Affected Systems

The vulnerability affects Joomla CMS versions between 4.0.0 and 5.4.7, as well as 6.0.0 to 6.1.2. Any site running one of these releases hosts the vulnerable webservice endpoints and may allow unauthenticated users to create custom fields for otherwise protected components.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves sending crafted HTTP requests to the webservice endpoints, exploiting the missing ACL checks to create fields without proper authorization. The exploitability depends on the attacker’s ability to reach these endpoints and the level of webserver exposure.

Generated by OpenCVE AI on August 18, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Joomla security release that fixes improper ACL checks for custom field webservice endpoints
  • If a patch is not yet available, restrict or disable the custom fields webservice endpoints for non‑admin users by updating ACLs or enforcing server‑level blocks
  • Review existing custom fields on the site for unauthorized additions and remove or correct them

Generated by OpenCVE AI on August 18, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla joomla\!
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla joomla\!
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
Title Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-19T04:49:03.457Z

Reserved: 2026-08-10T09:55:41.607Z

Link: CVE-2026-72531

cve-icon Vulnrichment

Updated: 2026-08-18T19:03:26.011Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T17:17:02.477

Modified: 2026-09-03T15:03:14.153

Link: CVE-2026-72531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:19Z

Weaknesses