Executive brief
iCagenda is an events management extension for Joomla that allows administrators to create and manage a calendar of events. A flaw in access control allows backend operators with limited permissions (scoped only to iCagenda) to enumerate and view all Joomla user profiles they should not have access to, potentially exposing user account details.
Technical details
This vulnerability is an Access Control List (ACL) bypass in the iCagenda extension for Joomla. A backend operator granted minimal permissions restricted to the `com_icagenda` component can circumvent scope restrictions to enumerate Joomla user profiles that fall outside their assigned permissions. The vulnerability allows direct enumeration of users without authentication escalation, leveraging insufficient access control checks in the component. The flaw affects versions below 2.0.0-4.0.11. A patch is available in version 2.0.0-4.0.11 and later.
Affected products
- JoomliC iCagenda < 2.0.0-4.0.11
Timeline
- 2026-08-14: disclosed