Description
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
Published: 2026-08-27
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-user event and venue takeover
Action: Assess Impact
AI Analysis

Impact

A registered user who has permission to edit own events can submit a POST request in which the record ID of another user’s event and the creator ID of the attacker’s own user ID are combined. This allows the attacker to assume ownership of the target event or venue. The flaw is an authorization bypass that compromises the integrity of event data, potentially leading to the unauthorized disclosure or modification of schedule information and venue responsibilities. The weakness is documented as CWE-639, Authorization Bypass through User-Controlled Key.

Affected Systems

Joomla Event Manager extension for Joomla, provided by joomlaeventmanager.net. Versions prior to 5.0.1 are affected.

Risk and Exploitability

The vulnerability has a CVSS score of 5.1, indicating moderate severity. No EPSS value is available, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires an authenticated user who can edit own events and the ability to craft a POST request with forged form fields, which is likely achievable through web interfaces or automated scripts. When exploited, an attacker can hijack control of events or venues belonging to other users.

Generated by OpenCVE AI on August 27, 2026 at 07:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Joomla Event Manager to version 5.0.1 or later to remove the flaw.
  • Restrict user accounts by revoking or limiting the ‘edit own’ permission so that only trusted administrators can modify event or venue records.
  • Investigate and audit event and venue records for unauthorized ownership changes, and correct any that have been compromised.

Generated by OpenCVE AI on August 27, 2026 at 07:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomlaeventmanager.net
Joomlaeventmanager.net jem - Joomla Event Manager Extension For Joomla
Vendors & Products Joomlaeventmanager.net
Joomlaeventmanager.net jem - Joomla Event Manager Extension For Joomla

Thu, 27 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
Title Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Joomlaeventmanager.net Jem - Joomla Event Manager Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-28T07:43:42.197Z

Reserved: 2026-08-20T08:56:32.577Z

Link: CVE-2026-77035

cve-icon Vulnrichment

Updated: 2026-08-27T13:50:44.188Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T06:17:28.120

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-77035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:32:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key