Improper Access Control in Joomla’s Configuration Webservice
CVE-2026-35223

8.6HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-35223?

An improper access control vulnerability exists in Joomla's configuration webservice, specifically in the com_config endpoints. This flaw allows attackers to gain unauthorized access, potentially compromising sensitive information and system integrity. It is crucial for Joomla users to implement recommended patches and security measures to safeguard their installations.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.5

Joomla! CMS 6.0.0-6.1.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rishi Shakya
Qi Deng
.