Description
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions.
Published: 2026-08-25
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing access check in YOOtheme Pro allows users with com_template editing rights to view data from any Joomla module, thereby exposing privileged configuration or sensitive content. This flaw represents a classic access control weakness (CWE‑284). The attacker can obtain information that may aid in further attacks such as social engineering or targeted exploitation of module features.

Affected Systems

The vulnerability affects the YOOtheme Pro extension for Joomla, versions 1.0.0 through 5.0.41. Users running any of these revision ranges are affected.

Risk and Exploitability

The CVSS score of 5.1 denotes moderate severity. Because the issue requires authenticated access and the EPSS is not available, the likelihood of exploitation is uncertain but potentially low. The vulnerability is not listed in CISA KEV, indicating no publicly known active exploitation. An attacker would need to be granted com_template editing permissions; no remote code execution or privilege escalation is described.

Generated by OpenCVE AI on August 25, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update YOOtheme Pro to version 5.0.42 or later, if available, to apply the vendor fix.
  • Revoke or limit com_template edit permissions for users who do not need access to module configuration.
  • Review and tighten Joomla’s Access Control Lists to ensure users only receive the permissions required for their roles.
  • Monitor module access logs for unauthorized queries and alert on abnormal activity.

Generated by OpenCVE AI on August 25, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.yootheme.com/ cve-icon cve-icon
History

Tue, 25 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions.
Title Joomla Extension - yootheme.com - Authenticated, privileged information disclosure about site modules YOOtheme Pro 1.0.0-5.0.40
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-25T13:04:10.377Z

Reserved: 2026-08-21T19:23:55.924Z

Link: CVE-2026-77997

cve-icon Vulnrichment

Updated: 2026-08-25T12:52:20.510Z

cve-icon NVD

Status : Received

Published: 2026-08-25T12:16:26.167

Modified: 2026-08-25T13:19:30.643

Link: CVE-2026-77997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T13:30:17Z

Weaknesses