Improper ACL Checks in Joomla! Core Affecting Multiple Versions
CVE-2026-90913
7HIGH
What is CVE-2026-90913?
An improper access control vulnerability exists in the Joomla! Core that allows unauthorized users to perform mutation actions via webservice endpoints. This issue affects Joomla versions 4.0.0 through 5.4.8 and 6.0.0 through 6.1.3, potentially exposing sensitive data and allowing malicious users to manipulate content or settings. It’s crucial for users of these affected versions to apply security patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.8
Joomla! CMS 6.0.0-6.1.3