Broken Object-Level Authorization in Joomla Helix Ultimate by JoomShaper
CVE-2026-78075

5.1MEDIUM

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-78075?

The Helix Ultimate extension from JoomShaper contains a faulty implementation regarding image deletion permissions. Specifically, the method responsible for removing images fails to comprehensively verify the user's rights to delete the specified image, as it only checks the authorization against the article ID within the request. This oversight allows users to leverage their permissions to delete arbitrary files from the server under the /images/ directory, which could lead to significant data loss or manipulation if exploited.

Affected Version(s)

Helix Ultimate extension for Joomla 1.0-2.2.9

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.