CVE-2026-21629

Publication date

2026-04-01 09:03:37

Family

Joomla

State

PUBLISHED

Description

The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.