CVE-2026-49049
published 2026-06-29CVE-2026-49049: The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and…
PriorityP182high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
0.99%
59.6th percentile
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomshaper.com | helix3_extension_for_joomla | — | — |
| ollyo | helix3 | 1.0 – 3.1.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
joomshaper Helix3 Extension 1.0-3.1.1 on Joomla JSON File access control (EUVD-2026-40122)
vuldb·2026-07-04·CVSS 7.5
CVE-2026-49049 [HIGH] joomshaper Helix3 Extension 1.0-3.1.1 on Joomla JSON File access control (EUVD-2026-40122)
A vulnerability classified as critical has been found in joomshaper Helix3 Extension 1.0-3.1.1 on Joomla. Affected by this issue is some unknown functionality of the component JSON File Handler. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2026-49049. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
ghsa_unreviewed·2026-06-29
CVE-2026-49049 [HIGH] CWE-284 The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
VulnCheck
ollyo helix3 Improper Access Control
vulncheck·2026·CVSS 7.5
CVE-2026-49049 [HIGH] ollyo helix3 Improper Access Control
ollyo helix3 Improper Access Control
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
Affected: ollyo helix3
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.com/CVE-2026-49049
Exploit PoC: https://vulncheck.com/xdb/b4600071f8d9; https://vulncheck.com/xdb/9b09e0f5fd1d; https://vulncheck.com/xdb/418f4dc859d2
No detection rules found.
Nuclei
JoomShaper Helix3 <=3.1.0 - Unauthenticated Arbitrary JSON File Write
nuclei·CVSS 7.5
CVE-2026-49049 [HIGH] JoomShaper Helix3 <=3.1.0 - Unauthenticated Arbitrary JSON File Write
JoomShaper Helix3 <=3.1.0 - Unauthenticated Arbitrary JSON File Write
JoomShaper Helix3 template framework versions 1.0 through 3.1.0 for Joomla expose an unauthenticated AJAX handler (plg_ajax_helix3) accessible via the Joomla com_ajax component. The onAjaxHelix3() plugin method processes data[action]=save requests without any authentication check or CSRF token validation. Unauthenticated remote attackers can write arbitrary JSON content to server-side files. The layoutName parameter contains no path traversal validation, enabling write to any directory writable by the web server process. Actively exploited in the wild by the AntonKill botnet campaign.
Template:
id: CVE-2026-49049
info:
name: JoomShaper Helix3 <=3.1.0 - Unauthenticated Arbitrary JSON File Write
author: DhiyaneshDk,pdt
No writeups or analysis indexed.
2026-06-29
Published
Exploited in the wild