SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-72532

MEDIUM · CVSS 5.4 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Joomla! versions 4.0.0 to 5.4.7 and 6.0.0 to 6.1.2 are vulnerable due to improper access control checks in their category webservice endpoints, enabling unauthorized users to create categories. This could lead to unauthorized modifications and potential disruption of content management. Organizations using these Joomla! versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-72532
Severity
MEDIUM
CVSS
5.4
EPSS
0.19%

Original NVD Description

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.

Related CVEs

Other vulnerabilities affecting the same vendor(s)