Access Control Flaw in Joomla Extension from JoomShaper
CVE-2026-78076

5.1MEDIUM

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-78076?

The Helix Ultimate template from JoomShaper contains a vulnerability related to broken access controls in its MegaMenu settings. The AJAX endpoint 'save-megamenu-settings' does not adequately enforce permissions at item and menu levels. As a result, authenticated users can manipulate layout parameters for any menu item without proper authorization, potentially leading to unauthorized changes in menu configurations.

Affected Version(s)

Helix Ultimate extension for Joomla 1.0-2.2.9

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.