CVE-2026-35223
Analyzed Analyzed - Analysis Complete
Improper Access Check in Joomla CMS

Publication date: 2026-05-26

Last updated on: 2026-05-28

Assigner: Joomla! Project

Description
An improper access check allows unauthorized access to com_config webservice endpoints.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-28
Generated
2026-06-16
AI Q&A
2026-05-26
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
joomla joomla! From 4.0.0 (inc) to 5.4.6 (exc)
joomla joomla! From 6.0.0 (inc) to 6.1.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-35223 is a security vulnerability in Joomla! CMS versions 4.0.0 to 5.4.5 and 6.0.0 to 6.1.0. It involves improper access checks in the com_config webservice endpoints, which allows unauthorized users to gain access to these endpoints.

This means that the system does not properly verify whether a user has the right permissions before allowing access to certain configuration webservice functions.

Impact Analysis

This vulnerability can have a high impact because unauthorized users might gain access to sensitive configuration settings through the com_config webservice endpoints.

Such unauthorized access could lead to changes in system configuration, potentially compromising the security and stability of the Joomla! CMS installation.

However, the probability of exploitation is considered low.

Users are advised to upgrade to Joomla! versions 5.4.6 or 6.1.1 or later to mitigate this risk.

Mitigation Strategies

To mitigate this vulnerability, users should upgrade Joomla! CMS to the fixed versions 5.4.6 or 6.1.1 or later.

This update addresses the improper access checks in the com_config webservice endpoints that allow unauthorized access.

Applying the update promptly reduces the risk of exploitation.

Compliance Impact

The provided information does not specify how the improper access check vulnerability in Joomla! CMS affects compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-35223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart