• Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71574

Description

An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Paul, Sorrachat, tms