Broken Object-Level Authorization in Joomla Helix Ultimate by JoomShaper
CVE-2026-78075
5.1MEDIUM
What is CVE-2026-78075?
The Helix Ultimate extension from JoomShaper contains a faulty implementation regarding image deletion permissions. Specifically, the method responsible for removing images fails to comprehensively verify the user's rights to delete the specified image, as it only checks the authorization against the article ID within the request. This oversight allows users to leverage their permissions to delete arbitrary files from the server under the /images/ directory, which could lead to significant data loss or manipulation if exploited.
Affected Version(s)
Helix Ultimate extension for Joomla 1.0-2.2.9
