Junglewise Threat Intelligence

CVE-2026-76610: YOOtheme Zoo unauthenticated tag modification via missing ACL checks

CVE-2026-76610 · Severity: info · Published 2026-08-20

Technologies: YOOtheme Zoo. Vendors: YOOtheme.

Executive brief

YOOtheme Zoo is a content management extension for Joomla used to organize and display custom content types. A flaw in the comment controller endpoint allows unauthenticated users to modify item tags without proper authorization checks, potentially altering site content and metadata without legitimate access rights.

Technical details

The vulnerability is an authorization bypass (missing ACL checks) in the Zoo comment controller endpoint. The comment controller fails to validate user permissions before processing tag modification requests, allowing any unauthenticated user to submit requests that modify tags on items. The attack is network-accessible and requires no authentication or special preconditions. An attacker can arbitrarily alter tag associations on Zoo items, affecting content categorization and discoverability. The issue is resolved in Zoo version 4.1.65 and later.

Affected products

  • YOOtheme Zoo < 4.1.65

Timeline

  • 2026-08-20: disclosed

References

Related threats