CVE-2026-35223
Received Received - Intake
Improper Access Check in Joomla CMS

Publication date: 2026-05-26

Last updated on: 2026-05-26

Assigner: Joomla! Project

Description
An improper access check allows unauthorized access to com_config webservice endpoints.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-26
Generated
2026-05-26
AI Q&A
2026-05-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
joomla cms From 4.0.0 (inc) to 5.4.5 (inc)
joomla cms From 6.0.0 (inc) to 6.1.0 (inc)
joomla cms 5.4.6
joomla cms 6.1.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The provided information does not specify how the improper access check vulnerability in Joomla! CMS affects compliance with common standards and regulations such as GDPR or HIPAA.


Can you explain this vulnerability to me?

CVE-2026-35223 is a security vulnerability in Joomla! CMS versions 4.0.0 to 5.4.5 and 6.0.0 to 6.1.0. It involves improper access checks in the com_config webservice endpoints, which allows unauthorized users to gain access to these endpoints.

This means that the system does not properly verify whether a user has the right permissions before allowing access to certain configuration webservice functions.


How can this vulnerability impact me? :

This vulnerability can have a high impact because unauthorized users might gain access to sensitive configuration settings through the com_config webservice endpoints.

Such unauthorized access could lead to changes in system configuration, potentially compromising the security and stability of the Joomla! CMS installation.

However, the probability of exploitation is considered low.

Users are advised to upgrade to Joomla! versions 5.4.6 or 6.1.1 or later to mitigate this risk.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, users should upgrade Joomla! CMS to the fixed versions 5.4.6 or 6.1.1 or later.

This update addresses the improper access checks in the com_config webservice endpoints that allow unauthorized access.

Applying the update promptly reduces the risk of exploitation.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart