Unauthenticated Access Control Bypass in JoomGallery by Joomla Extension
CVE-2026-66916

6.9MEDIUM

What is CVE-2026-66916?

An unauthenticated access control bypass vulnerability exists in the JoomGallery extension for Joomla. When a gallery category is secured with a password, the standard HTML view successfully enforces this password requirement. However, the JSON view does not enforce the same checking protocols, allowing unauthorized users to gain access to password-protected gallery categories via the JSON endpoint. This flaw could potentially expose sensitive content that is meant to be restricted, thereby compromising the integrity of the access control mechanisms.

Affected Version(s)

JoomGallery extension for Joomla 4.0.0-4.3.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Toan Le
.