Junglewise Threat Intelligence

CVE-2026-71570: JoomliC iCagenda ACL bypass in user enumeration

CVE-2026-71570 · Severity: info · Published 2026-08-14

Technologies: JoomliC iCagenda.

Executive brief

iCagenda is an events management extension for Joomla that allows administrators to create and manage a calendar of events. A flaw in access control allows backend operators with limited permissions (scoped only to iCagenda) to enumerate and view all Joomla user profiles they should not have access to, potentially exposing user account details.

Technical details

This vulnerability is an Access Control List (ACL) bypass in the iCagenda extension for Joomla. A backend operator granted minimal permissions restricted to the `com_icagenda` component can circumvent scope restrictions to enumerate Joomla user profiles that fall outside their assigned permissions. The vulnerability allows direct enumeration of users without authentication escalation, leveraging insufficient access control checks in the component. The flaw affects versions below 2.0.0-4.0.11. A patch is available in version 2.0.0-4.0.11 and later.

Affected products

  • JoomliC iCagenda < 2.0.0-4.0.11

Timeline

  • 2026-08-14: disclosed

References