Junglewise Threat Intelligence

CVE-2026-77990: Joomla Event Manager attendee list unauthorized disclosure

CVE-2026-77990 · Severity: info · Published 2026-08-27

Technologies: Joomla Event Manager.

Executive brief

Joomla Event Manager is a free extension for Joomla that manages events, registrations, and attendee information. In versions before 5.0.1, any logged-in user (not just event managers) could read attendee lists for events they do not manage, exposing names, usernames, registration dates, and participation statuses—including for unpublished events. This represents a privacy breach where sensitive attendee data intended for event organizers becomes visible to unauthorized users.

Technical details

The vulnerability is an improper access control flaw in Joomla Event Manager's attendee list functionality. The extension fails to properly enforce role-based authorization (ACL), allowing any authenticated user to view attendee lists regardless of their event-management permissions. The attack vector is network-based and requires only valid Joomla user credentials; no elevation of privileges or social engineering is necessary. An authenticated attacker can enumerate attendee data, registration details, and event participation status for events they have no legitimate access to. The vulnerability is fixed in version 5.0.1, which implements granular backend ACL for events, venues, and attendees.

Affected products

  • Joomla Event Manager Joomla Event Manager < 5.0.1

Timeline

  • 2026-08-27: disclosed
  • 2026-09-14: patched: JEM 5.0.1 released with granular backend ACL

References