CVE-2026-23898External Control of File Name or Path in Joomla !

Severity
8.6HIGHNVD
EPSS
0.0%
top 99.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1

Description

Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDjoomla/joomla_!3.0.05.4.4+1
CVEListV5joomla!_project/joomla!_cms4.0.0-5.4.3, 6.0.0-6.0.3+1

🔴Vulnerability Details

2
CVEList
Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate2026-04-01
GHSA
GHSA-m9qp-xh66-cmcx: Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism2026-04-01

🕵️Threat Intelligence

1
Wiz
CVE-2026-23898 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23898 — External Control of File Name or Path | cvebase