CVE-2026-76610
Received Received - Intake

Unauthenticated Tag Modifications in YOOtheme Zoo Extension

Vulnerability report for CVE-2026-76610, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Joomla! Project

Description

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yootheme joomla_extension to 4.1.65 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated users to modify tags in the Joomla extension Zoo through the comment controller endpoint due to missing access control list (ACL) checks. The affected version is Zoo prior to 4.1.65.

Detection Guidance

This vulnerability involves unauthenticated tag modifications in the Zoo extension for Joomla. To detect it, check if your Joomla site uses Zoo extension version below 4.1.65. Inspect server logs for unauthorized POST requests to the comment controller endpoint. Look for suspicious tag modifications in the database.

Impact Analysis

An attacker could exploit this to alter tags without authentication, potentially leading to unauthorized content changes, data integrity issues, or disruption of website functionality. This could affect site operations and user experience.

Compliance Impact

The vulnerability allows unauthenticated users to modify tags without access controls, which could lead to unauthorized changes in data classification or metadata. This may impact compliance by potentially exposing or altering sensitive data, though specific regulatory impacts depend on how tags are used in the affected system.

Mitigation Strategies

Update the Zoo extension to version 4.1.65 or later to address the unauthenticated tag modification vulnerability. Remove or disable the affected extension if updating is not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76610. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart