Path Traversal Vulnerability in Joomla's com_media API Endpoint
CVE-2026-40384

5.9MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-40384?

An improper validation of the search parameter in Joomla's com_media files API endpoint creates a path traversal vulnerability that enables attackers to access restricted directories and potentially execute malicious files. Proper validation mechanisms must be in place to prevent unauthorized access when utilizing this API.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.5

Joomla! CMS 6.0.0-6.1.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Doyensec in collaboration with Claude and Anthropic Research
.