SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-71574

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Joomla! versions 4.0.0 to 6.1.2 are vulnerable due to inconsistent access control checks in webservice endpoints, allowing unauthorized users to perform actions that should be restricted. This could lead to unauthorized data manipulation and compromise the integrity of the application. Organizations using affected Joomla! versions should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-71574
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%

Original NVD Description

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

Related CVEs

Other vulnerabilities affecting the same vendor(s)