Description
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
Published: 2026-08-18
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control in Joomla! core that allows an unauthorized user to create categories through the webservice endpoints. This flaw could let an attacker add categories they should not have permission to create, potentially enabling further malicious activity or disrupting site organization. It is inferred that both unauthenticated and insufficiently privileged users can trigger this flaw, as the access check does not verify appropriate rights before allowing category creation.

Affected Systems

Joomla! CMS, released under the Joomla! Project, is affected in all versions from 4.0.0 through 5.4.7 and from 6.0.0 through 6.1.2. Users running any of these releases should verify whether their installation falls within these version ranges.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers can leverage the exposed webservice endpoints to create categories without proper authorization, typically by sending requests to the affected APIs. No authentication or elevated permissions are required beyond normal site access, making the flaw remotely exploitable for unauthorized category creation.

Generated by OpenCVE AI on August 18, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Address the improper access control flaw (CWE-284) by installing the latest Joomla! security update that patches the ACL check.
  • Enforce strict ACL permissions on the category creation webservice endpoint so that only users with administrator or editor roles may invoke it, preventing unauthorized category creation.
  • Block access to the vulnerable webservice endpoint with a webserver rule or firewall until a patch or ACL configuration is applied.
  • If a patch cannot be applied immediately, temporarily disable the category creation endpoint via the application’s configuration or a custom plugin, ensuring no unauthorized requests succeed.

Generated by OpenCVE AI on August 18, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla joomla\!
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla joomla\!
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 17:30:00 +0000


Tue, 18 Aug 2026 16:30:00 +0000


Tue, 18 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
Title Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-19T04:44:33.513Z

Reserved: 2026-08-10T09:55:41.608Z

Link: CVE-2026-72532

cve-icon Vulnrichment

Updated: 2026-08-18T19:05:58.319Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T16:18:16.593

Modified: 2026-09-03T15:07:27.047

Link: CVE-2026-72532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:31Z

Weaknesses