CVE-2026-71574
published 2026-08-18CVE-2026-71574: Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.20%
10.2th percentile
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_cms | — | — |
| joomla | joomla_! | >= 4.0.0 < 5.4.8 | 5.4.8 |
| joomla | joomla_! | >= 6.0.0 < 6.1.3 | 6.1.3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.08.5HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Joomla! Project Joomla! CMS Extension up to 5.4.6/6.1.2 Webservice Endpoint improper authorization (WID-SEC-2026-2926)
vuldb·2026-09-06·CVSS 6.5
CVE-2026-71574 [MEDIUM] Joomla! Project Joomla! CMS Extension up to 5.4.6/6.1.2 Webservice Endpoint improper authorization (WID-SEC-2026-2926)
A vulnerability has been found in Joomla! Project Joomla! CMS Extension up to 5.4.6/6.1.2 and classified as problematic. This impacts an unknown function of the component Webservice Endpoint. This manipulation causes improper authorization.
This vulnerability is tracked as CVE-2026-71574. The attack is possible to be carried out remotely. No exploit exists.
GHSA
GHSA-h4xv-fj9g-wcrv: Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4
ghsa_unreviewed·2026-08-18
CVE-2026-71574 [HIGH] CWE-284 GHSA-h4xv-fj9g-wcrv: Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-18
Published