Vulnerability in Joomla Ajax Component Affects Security Checks
CVE-2026-21629

6.3MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
1 April 2026

What is CVE-2026-21629?

The ajax component in Joomla Core fails to perform the necessary checks for logged-in users in the administrative area, potentially exposing the system to unauthorized actions. This issue may lead to unexpected behavior for developers utilizing this component in their extensions, impacting the overall security posture of Joomla installations.

Affected Version(s)

Joomla! CMS 3.0.0-5.4.3

Joomla! CMS 6.0.0-6.0.3

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joomla Security Strike Team
.