Insecure Default Configuration in Joomdle Extension for Joomla by Joomdle
CVE-2026-65881

Currently unrated

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-65881?

The Joomdle extension for Joomla has a vulnerability caused by an insecure default configuration that permits unauthorized read and write access to user accounts. Users may exploit this flaw to gain access to sensitive account details and even reset passwords, potentially compromising entire CMS installations. It is crucial for users of Joomdle versions prior to 3.1.1 to review their configuration settings to mitigate these risks.

Affected Version(s)

Joomdle component for Joomla 0.7.0-3.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.