Junglewise Threat Intelligence

CVE-2026-78074: miniOrange Joomla Extensions unauthenticated arbitrary extension deinstallation

CVE-2026-78074 · Severity: info · Published 2026-08-31

Executive brief

Various free Joomla plugins from miniOrange are vulnerable to unauthenticated removal of any installed extension due to missing authentication checks. An attacker on the network can delete critical plugins without logging in, disrupting site functionality and potentially making a Joomla installation inoperable.

Technical details

The vulnerability is an authentication bypass (CWE-306) in multiple free miniOrange Joomla plugins. A missing authentication check in the extension deinstallation function allows unauthenticated remote attackers to construct requests that trigger arbitrary extension removal. No special privileges, valid credentials, or user interaction are required; network access to the Joomla installation is sufficient. An attacker can systematically delete all installed extensions, rendering the site inoperable. Only free versions of miniOrange plugins are affected; paid versions likely contain the authentication controls.

Affected products

  • miniOrange Joomla Extensions (free versions) free versions only

Timeline

  • 2026-08-31: disclosed

References