Executive brief
Joomla! CMS, a popular platform for building websites, contains a security flaw in its media management API. An attacker with high-level administrative privileges could exploit this to access files outside of the intended media folders. This could lead to the exposure of sensitive system files or configuration data, potentially compromising the entire website.
Technical details
A path traversal vulnerability exists in the Joomla! CMS 'com_media' web service endpoint due to insufficient validation of the 'search' parameter. An authenticated attacker with high privileges (PR:H) can submit specially crafted requests to bypass directory restrictions. This allows for unauthorized read access to files on the server filesystem that should be inaccessible to the media manager. The vulnerability affects Joomla! versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. It has been addressed in versions 5.4.6 and 6.1.1.
Affected products
- Joomla! CMS 4.0.0 - 5.4.5, 6.0.0 - 6.1.0
Timeline
- 2026-04-15: disclosed: Reported by Doyensec in collaboration with Claude and Anthropic Research
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: advisory