Description
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
Published: 2026-08-27
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A registered user who has permission to edit own events can submit a POST request in which the record ID of another user’s event and the creator ID of the attacker’s own user ID are combined. This allows the attacker to assume ownership of the target event or venue. The flaw is an authorization bypass that compromises the integrity of event data, potentially leading to the unauthorized disclosure or modification of schedule information and venue responsibilities. The weakness is documented as CWE-639, Authorization Bypass through User-Controlled Key.

Affected Systems

Joomla Event Manager extension for Joomla, provided by joomlaeventmanager.net. Versions prior to 5.0.1 are affected.

Risk and Exploitability

The vulnerability has a CVSS score of 5.1, indicating moderate severity. No EPSS value is available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires an authenticated user who can edit own events and the ability to craft a POST request with forged form fields, which is likely achievable through web interfaces or automated scripts. When exploited, an attacker can hijack control of events or venues belonging to other users.

Generated by OpenCVE AI on August 27, 2026 at 07:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Joomla Event Manager to version 5.0.1 or later to remove the flaw.
  • Restrict user accounts by revoking or limiting the ‘edit own’ permission so that only trusted administrators can modify event or venue records.
  • Investigate and audit event and venue records for unauthorized ownership changes, and correct any that have been compromised.

Generated by OpenCVE AI on August 27, 2026 at 07:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
Title Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-27T05:46:06.829Z

Reserved: 2026-08-20T08:56:32.577Z

Link: CVE-2026-77035

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T06:17:28.120

Modified: 2026-08-27T06:17:28.120

Link: CVE-2026-77035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T07:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key