CVE-2026-75951
Received Received - Intake

Insecure Direct Object Reference in J-BusinessDirectory Joomla Extension

Vulnerability report for CVE-2026-75951, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Joomla! Project

Description

Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cmsjunkie j-businessdirectory to 6.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) affecting the J-BusinessDirectory Joomla extension versions before 6.2.3. IDOR allows attackers to access or manipulate objects directly by manipulating object references in requests, potentially leading to unauthorized data access or actions.

Detection Guidance

This vulnerability is an Insecure Direct Object Reference in J-BusinessDirectory versions before 6.2.3. Detection requires checking the installed version of the extension. Use Joomla's admin panel to verify the version or check the extension's files for version details in the manifest file.

Impact Analysis

An attacker could exploit this to access sensitive data, modify or delete records, or perform unauthorized actions in the J-BusinessDirectory extension. This could lead to data breaches, loss of business data, or disruption of services if exploited.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Update J-BusinessDirectory to version 6.2.3 or later to address the Insecure Direct Object Reference vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75951. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart