Executive brief
Joomla! CMS is a popular platform used to build and manage websites. A security flaw in the media management component allows users with high-level administrative access to overwrite existing media files even if they do not have specific permissions to edit them. This could lead to unauthorized modification of website content or assets by internal users exceeding their intended authority.
Technical details
An incorrect access control vulnerability (CWE-284) exists within the com_media webservice endpoints of Joomla! CMS. The root cause is an improper access check that fails to validate specific editing permissions for privileged users attempting to overwrite media files. An attacker with high-privileged credentials (PR:H) can exploit this over the network without user interaction to modify files they should not have access to change. The vulnerability affects Joomla! CMS versions 4.1.0 through 5.4.6 and 6.0.0 through 6.1.1. Users are advised to upgrade to versions 5.4.7 or 6.1.2 to remediate the issue.
Affected products
- Joomla! Project Joomla! CMS 4.1.0-5.4.6, 6.0.0-6.1.1
Timeline
- 2026-05-05: other: Reported date
- 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
- 2026-07-07: disclosed: CVE published