SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77034

MEDIUM · CVSS 6.9 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Joomla Event Manager extension prior to version 5.0.1 is vulnerable to unauthenticated article overwrite and force-publishing, allowing any visitor with a valid session token to modify and republish articles linked to events. This could lead to unauthorized content manipulation, potentially damaging the integrity of event information. Joomla administrators and users of the affected extension should prioritize applying the update to mitigate this risk.

CVE
CVE-2026-77034
Severity
MEDIUM
CVSS
6.9
EPSS
0.24%

Original NVD Description

Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.