- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-15
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-71574
Description
An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
Reported By: Paul, Sorrachat, tms