SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78074

HIGH · CVSS 8.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated users to delete arbitrary installed extensions in the free versions of miniOrange plugins for Joomla due to a lack of authentication checks. This could lead to significant disruptions in website functionality and potential data loss for affected sites. Joomla administrators using the free miniOrange extensions should prioritize remediation to mitigate the risk of unauthorized extension deinstallation.

CVE
CVE-2026-78074
Severity
HIGH
CVSS
8.8
EPSS
0.31%

Original NVD Description

Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.