Unauthenticated Deinstallation Vulnerability in miniOrange Joomla Extensions by miniOrange
CVE-2026-78074

8.8HIGH

What is CVE-2026-78074?

A security vulnerability in the free versions of the miniOrange extensions for Joomla allows unauthenticated users to delete arbitrary installed extensions. The lack of proper authentication checks in these plugins exposes Joomla websites to risks, permitting unauthorized individuals to manipulate and remove critical site components without permission. This vulnerability highlights the importance of robust authentication mechanisms in safeguarding web applications.

Affected Version(s)

Custom API for Joomla (free) extension for Joomla 1.0.0-4.2

Import Export Users for Joomla (free) extension for Joomla 1.0.0-4.6

JoomAI - AI Assistant for Joomla (free) extension for Joomla 1.0.0-1.0.5

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.