Junglewise Threat Intelligence

CVE-2026-35223: Joomla! CMS improper access check in com_config webservice endpoints

CVE-2026-35223 · Severity: info · CVSS 8.6 · Published 2026-05-26

Technologies: Joomla CMS. Vendors: Joomla.

Executive brief

Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in its configuration web service. This vulnerability could allow an unauthorized user to access sensitive configuration settings, potentially leading to a full compromise of the website's data and operations. Organizations should update their Joomla! installations to the latest patched versions to prevent unauthorized administrative changes.

Technical details

An improper access control vulnerability (CWE-284) exists within the com_config component of Joomla! CMS. The flaw is located in the webservice endpoints, where insufficient validation of user permissions allows unauthorized access to configuration actions. While the CVSS vector indicates high privileges are required (PR:H), an exploit allows for high impact on confidentiality, integrity, and availability. The vulnerability affects Joomla! versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. It has been addressed in versions 5.4.6 and 6.1.1.

Affected products

  • Joomla! CMS 4.0.0-5.4.5, 6.0.0-6.1.0

Timeline

  • 2026-04-15: other: Reported date
  • 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
  • 2026-05-26: disclosed: Public advisory published

References