Improper Access Control in Joomla’s Configuration Webservice
CVE-2026-35223
8.6HIGH
What is CVE-2026-35223?
An improper access control vulnerability exists in Joomla's configuration webservice, specifically in the com_config endpoints. This flaw allows attackers to gain unauthorized access, potentially compromising sensitive information and system integrity. It is crucial for Joomla users to implement recommended patches and security measures to safeguard their installations.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.5
Joomla! CMS 6.0.0-6.1.0