CVE-2026-72531
Analyzed Analyzed - Analysis Complete

Improper ACL Checks in Joomla Core Webservice

Vulnerability report for CVE-2026-72531, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-09-03

Assigner: Joomla! Project

Description

Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-09-03
Generated
2026-09-07
AI Q&A
2026-08-18
EPSS Evaluated
2026-09-06
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
joomla joomla! From 4.0.0 (inc) to 5.4.8 (exc)
joomla joomla! From 6.0.0 (inc) to 6.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Joomla! Core affects versions 4.0.0-5.4.7 and 6.0.0-6.1.2 due to improper access control list (ACL) checks for custom fields webservice endpoints. It allows unauthorized users to create fields for components they should not have access to.

Detection Guidance

This vulnerability involves improper ACL checks in Joomla's custom fields webservice endpoints. To detect it, inspect Joomla's web service logs for unauthorized field creation requests targeting inaccessible components. Check for POST requests to /api/index.php/v1/fields with unexpected component access. Review Joomla's access logs for repeated failed attempts to modify fields in restricted areas.

Impact Analysis

An attacker could exploit this to create unauthorized custom fields in restricted components, potentially leading to data exposure, privilege escalation, or further system compromise depending on the affected components.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations if exploited.

Mitigation Strategies

Update Joomla to the latest patched version (5.4.8 or later for Joomla 4.x, 6.1.3 or later for Joomla 6.x) to address the improper ACL checks in custom fields webservice endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72531. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart