Executive brief
Helix Ultimate is a popular framework and template used to build and design Joomla websites. A security vulnerability in this extension allows unauthorized individuals to delete files from the web server without needing to log in. This could lead to significant website disruption, loss of critical data, or a complete service outage as essential system files are removed.
Technical details
A vulnerability exists in the Helix Ultimate extension for Joomla (versions 1.0 through 2.2.6) classified as Missing Authorization (CWE-862). The flaw allows a remote, unauthenticated attacker to trigger the deletion of arbitrary files on the server by sending specially crafted requests. Because the component fails to verify user permissions before executing file deletion operations, an attacker can disrupt site operations or delete sensitive configuration files. The issue is addressed in version 2.2.8.
Affected products
- JoomShaper Helix Ultimate extension for Joomla 1.0-2.2.6
Timeline
- 2026-07-07: patched: Version 2.2.8 released
- 2026-07-13: advisory: CVE published by Joomla! Project and NVD