Unauthenticated Access Control Bypass in JoomGallery by Joomla Extension
CVE-2026-66916
6.9MEDIUM
What is CVE-2026-66916?
An unauthenticated access control bypass vulnerability exists in the JoomGallery extension for Joomla. When a gallery category is secured with a password, the standard HTML view successfully enforces this password requirement. However, the JSON view does not enforce the same checking protocols, allowing unauthorized users to gain access to password-protected gallery categories via the JSON endpoint. This flaw could potentially expose sensitive content that is meant to be restricted, thereby compromising the integrity of the access control mechanisms.
Affected Version(s)
JoomGallery extension for Joomla 4.0.0-4.3.0
