Improper Access Control in Joomla! Core Web Services
CVE-2026-92226

7HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-92226?

Joomla! Core experiences a significant vulnerability due to improper access control checks for various web service edit tasks, affecting multiple versions including 4.0.0 to 5.4.8 and 6.0.0 to 6.1.3. This flaw permits unauthorized users to perform edit actions on items that should otherwise be protected, potentially compromising sensitive data or functionality within the platform. To mitigate this risk, users are advised to update to the latest version of the Joomla! Core.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Google and Ada Logics
.