Access Control Flaw in Joomla Extension from JoomShaper
CVE-2026-78076
5.1MEDIUM
What is CVE-2026-78076?
The Helix Ultimate template from JoomShaper contains a vulnerability related to broken access controls in its MegaMenu settings. The AJAX endpoint 'save-megamenu-settings' does not adequately enforce permissions at item and menu levels. As a result, authenticated users can manipulate layout parameters for any menu item without proper authorization, potentially leading to unauthorized changes in menu configurations.
Affected Version(s)
Helix Ultimate extension for Joomla 1.0-2.2.9
