Improper Access Control in Joomla! Core Affects Webservice Endpoints
CVE-2026-72531
5.1MEDIUM
What is CVE-2026-72531?
An improper access control vulnerability in Joomla! Core affects the handling of custom fields webservice endpoints. This flaw enables unauthorized users to create custom fields for components that should otherwise be restricted. Versions 4.0.0 to 4.5.7 and 6.0.0 to 6.1.2 are particularly impacted. Proper measures should be taken to secure these endpoints and manage user permissions effectively.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.6
Joomla! CMS 6.0.0-6.1.2