CVE-2026-73372
Analyzed Analyzed - Analysis Complete

Improper ACL Check in Joomla Core

Vulnerability report for CVE-2026-73372, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-09-03

Assigner: Joomla! Project

Description

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-09-03
Generated
2026-09-08
AI Q&A
2026-08-18
EPSS Evaluated
2026-09-06
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
joomla joomla! From 5.1.0 (inc) to 5.4.8 (exc)
joomla joomla! From 6.0.0 (inc) to 6.1.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Joomla! CMS versions 5.1.0 to 5.4.7 and 6.0.0 to 6.1.2. It involves improper access control checks that allow injecting contact information for inaccessible contact items into schema.org snippets. Users without proper permissions could access restricted data through these snippets.

Detection Guidance

To detect this vulnerability, check your Joomla version against affected ranges (5.1.0-5.4.7 and 6.0.0-6.1.2). Inspect schema.org snippets for unauthorized contact data exposure. Review access logs for unusual requests to contact endpoints.

Impact Analysis

The impact is limited as the vulnerability has low severity. It could allow unauthorized users to view restricted contact data through schema.org snippets, potentially exposing sensitive information.

Compliance Impact

The vulnerability allows unauthorized access to restricted contact data through schema.org snippets, which could lead to exposure of personal information. This may violate data protection regulations like GDPR or HIPAA if such data includes personally identifiable information (PII) or protected health information (PHI). Organizations using affected Joomla versions must ensure proper access controls are enforced to maintain compliance.

Mitigation Strategies

Immediately upgrade Joomla to versions 5.4.8 or 6.1.3 or later. Apply the latest security patches from Joomla's official releases. Monitor for unauthorized access to contact data and review user permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73372. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart