CVE-2026-65755
Received Received - Intake

Date-Sensitive Query Cache Key Exposure in Joomla

Vulnerability report for CVE-2026-65755, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Joomla! Project

Description

Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-524 The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves date-sensitive query cache keys not retaining a proper time limit. Cached results could stay active beyond their intended expiry, potentially exposing content that should no longer be accessible.

Impact Analysis

Users might see outdated or expired content that should have been removed. This could lead to privacy issues or incorrect information being displayed after it was meant to be hidden.

Compliance Impact

The vulnerability could lead to unauthorized access to cached content that should have been expired or restricted, potentially violating data retention and access control requirements under GDPR and HIPAA.

Mitigation Strategies

Clear all cached content and disable caching temporarily until a patch is applied. Review cache configuration to ensure time-based expiration is enforced correctly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65755. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart