Executive brief
YOOtheme Zoo is a content management extension for Joomla used to organize and display custom content types. A flaw in the comment controller endpoint allows unauthenticated users to modify item tags without proper authorization checks, potentially altering site content and metadata without legitimate access rights.
Technical details
The vulnerability is an authorization bypass (missing ACL checks) in the Zoo comment controller endpoint. The comment controller fails to validate user permissions before processing tag modification requests, allowing any unauthenticated user to submit requests that modify tags on items. The attack is network-accessible and requires no authentication or special preconditions. An attacker can arbitrarily alter tag associations on Zoo items, affecting content categorization and discoverability. The issue is resolved in Zoo version 4.1.65 and later.
Affected products
- YOOtheme Zoo < 4.1.65
Timeline
- 2026-08-20: disclosed