Junglewise Threat Intelligence

CVE-2026-77034: Joomla Event Manager unauthenticated article overwrite and force-publish

CVE-2026-77034 · Severity: info · Published 2026-08-27

Technologies: Joomlaeventmanager.Net Joomla Event Manager. Vendors: Joomlaeventmanager.Net.

Executive brief

Joomla Event Manager is an open-source extension for Joomla that manages events, venues, calendars, and registrations. A vulnerability in versions before 5.0.1 allows any visitor with a session token to overwrite articles and force-publish them, potentially enabling unauthorized content modification or injection on event-related pages.

Technical details

The vulnerability is an authorization bypass in Joomla Event Manager's article handling. Any visitor holding their own session token can republish and overwrite articles associated with events without proper permission checks. The flaw affects versions prior to 5.0.1 and requires only that an attacker possess a valid session token (a low bar for unauthenticated or low-privilege users). Successful exploitation allows unauthorized content modification, defacement, or injection of malicious content into event-related articles. The vulnerability has been patched in version 5.0.1.

Affected products

  • joomlaeventmanager.net Joomla Event Manager < 5.0.1

Timeline

  • 2026-08-27: disclosed
  • 2026-09-14: patched: Fixed in JEM 5.0.1

References

Related threats