Description
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
Published: 2026-08-18
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an improper access control check that permits anyone to perform batch copy operations on items they are not permitted to edit. This flaw can lead to the creation of duplicate or unauthorized content, undermining the integrity and trustworthiness of the site’s data and potentially facilitating the spread of unapproved material. The flaw is classified as a CWE‑284: Improper Control of Access Permissions.

Affected Systems

The Joomla Content Management System is affected, specifically the core releases from Joomla 4.0.0 through 5.4.7 and from 6.0.0 through 6.1.2. Users operating these versions should review whether they can access the back‑end batch copy feature.

Risk and Exploitability

The CVSS base score of 5.1 indicates a medium severity vulnerability. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to the batch copy endpoint, which could be triggered by any user with access to the administrative interface or by any authenticated user with basic permissions. While the flaw does not enable code execution or credential theft, it can compromise content integrity and may be leveraged for malicious content duplication, especially in mis‑configured environments.

Generated by OpenCVE AI on August 18, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Joomla to the latest release that resolves the ACL check vulnerability.
  • If an immediate upgrade is not feasible, restrict or disable the batch copy ACR functionality until the issue is remediated, for example by adjusting permissions or using administrator‑only access.
  • Inspect the site for duplicated or unauthorized content that may have been created during the vulnerability window and correct or remove it as required.

Generated by OpenCVE AI on August 18, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla joomla\!
CPEs cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Vendors & Products Joomla joomla\!
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 17:30:00 +0000


Tue, 18 Aug 2026 16:30:00 +0000


Tue, 18 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.
Title Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-19T04:45:00.495Z

Reserved: 2026-08-12T14:00:09.041Z

Link: CVE-2026-73371

cve-icon Vulnrichment

Updated: 2026-08-18T19:05:37.050Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T16:18:17.040

Modified: 2026-09-03T15:00:36.247

Link: CVE-2026-73371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:29Z

Weaknesses