Inconsistent Access Control Checks in Joomla! Web Services
CVE-2026-71574
8.5HIGH
What is CVE-2026-71574?
An improper access check in Joomla! Core allows unauthorized users to perform mutation actions on webservice endpoints that should be restricted. This flaw is present in multiple versions, where inconsistent ACL (Access Control List) checks fail to properly restrict actions that are otherwise gated in the backend user interface.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.6
Joomla! CMS 6.0.0-6.1.2