CVE-2026-21626
Unknown
Unknown - Not Provided
Access Control Bypass in Joomla Forum Post JSON Causes Data Leak
Publication date: 2026-02-06
Last updated on: 2026-02-18
Assigner: Joomla! Project
Description
Description
Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violation vector an information disclosure
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| stackideas | easydiscuss | From 1.0.0 (inc) to 5.0.15 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |