Improper Access Control in Joomla! Core for Batch Copy Actions
CVE-2026-73371

5.1MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
18 August 2026

What is CVE-2026-73371?

An improper access control vulnerability in the Joomla! Core allows unauthorized users to execute batch copy operations on items that should be uneditable. This flaw, which affects numerous versions of Joomla, raises significant concerns regarding the integrity and security of content management within the platform.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.6

Joomla! CMS 6.0.0-6.1.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sabuhi Mammadov
.