Inconsistent Access Control Checks in Joomla! Web Services
CVE-2026-71574

8.5HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71574?

An improper access check in Joomla! Core allows unauthorized users to perform mutation actions on webservice endpoints that should be restricted. This flaw is present in multiple versions, where inconsistent ACL (Access Control List) checks fail to properly restrict actions that are otherwise gated in the backend user interface.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.6

Joomla! CMS 6.0.0-6.1.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Paul
Sorrachat
.