Security Advisory

CVE-2026-71574

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-18 16:02:54
Last updated 2026-08-21 08:59:30
Assigner Joomla
CVSS score 8.5
State PUBLISHED

Description

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.