Description
Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.
Published: 2026-08-31
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authentication check in the Joomla extensions from miniorgange.com allows an unauthenticated actor to delete any installed extension from the site. This flaw is an access control deficiency (CWE-284) that can disable critical functionality or remove security components, potentially leading to site disruption or facilitating further compromise.

Affected Systems

The vulnerability impacts only free versions of the miniOrange extensions for Joomla. The affected plugins include Custom API for Joomla, Import Export Users for Joomla, JoomAI – AI Assistant for Joomla, JoomShield, Keycloak user sync, LDAP Integration with Active Directory and OpenLDAP, Login with Keycloak OAuth SSO, OAuth Server, OAuth Single Sign-On – OIDC SSO, OTP Verification, Okta User sync, Restrict Files, SAML 2.0 IDP, SAML SP Single Sign On – Login with ADFS, SAML SSO login with google Apps, SCIM User Provisioning, Single Sign On for Educational Institutes, Staff/Employee Business Directory Search, Two Factor Authentication, Web3 – Crypto wallet Login & NFT token gating, miniOrange Oauth Client, and miniOrange User Provisioning with Azure. No specific version information is supplied, but all free editions are affected.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is classified as high severity. The EPSS score is not available and the issue is not listed in CISA KEV, indicating no confirmed exploits yet. The attack vector is likely remote and requires no authentication, allowing any unauthenticated web user with access to the Joomla administration interfaces to issue deletion requests. Because the flaw permits arbitrary extension removal, it can cause denial of service to site functionality and provide an avenue for attackers to disable or replace security extensions, elevating the potential impact.

Generated by OpenCVE AI on August 31, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all free miniOrange extensions to the latest release when a patch is issued
  • If no patch is available, remove or disable the affected free extensions from the Joomla site
  • Implement authentication and permission controls for extension management pages to prevent unauthenticated access
  • Deploy a web application firewall or rate limiting to block unauthenticated deletion requests

Generated by OpenCVE AI on August 31, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.
Title Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-31T14:24:07.581Z

Reserved: 2026-08-22T14:23:37.801Z

Link: CVE-2026-78074

cve-icon Vulnrichment

Updated: 2026-08-31T14:24:03.319Z

cve-icon NVD

Status : Received

Published: 2026-08-31T14:17:23.633

Modified: 2026-08-31T15:17:55.260

Link: CVE-2026-78074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T15:30:04Z

Weaknesses