Executive brief
Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in its configuration web service. This vulnerability could allow an unauthorized user to access sensitive configuration settings, potentially leading to a full compromise of the website's data and operations. Organizations should update their Joomla! installations to the latest patched versions to prevent unauthorized administrative changes.
Technical details
An improper access control vulnerability (CWE-284) exists within the com_config component of Joomla! CMS. The flaw is located in the webservice endpoints, where insufficient validation of user permissions allows unauthorized access to configuration actions. While the CVSS vector indicates high privileges are required (PR:H), an exploit allows for high impact on confidentiality, integrity, and availability. The vulnerability affects Joomla! versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. It has been addressed in versions 5.4.6 and 6.1.1.
Affected products
- Joomla! CMS 4.0.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-04-15: other: Reported date
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: disclosed: Public advisory published