CVE-2026-78074
Received Received - Intake

Unauthenticated Extension Deletion in miniOrange Joomla Plugins

Vulnerability report for CVE-2026-78074, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: Joomla! Project

Description

Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
miniorange plugin to free (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated arbitrary extension deinstallation vulnerability in various miniOrange Joomla extensions. It allows unauthenticated actors to delete any installed extensions due to a missing authentication check. Only the free versions of the miniOrange plugins are affected.

Detection Guidance

Check installed miniOrange Joomla extensions for unauthorized deinstallation attempts or logs showing unauthenticated access. Review Joomla admin logs for unusual extension management activities.

Impact Analysis

An attacker could exploit this to remove critical Joomla extensions, disrupting website functionality or security features. This could lead to loss of access, data exposure, or system compromise depending on which extensions are deleted.

Compliance Impact

The vulnerability allows unauthenticated deletion of extensions, which could disrupt security controls or data protection mechanisms. This may impact compliance with GDPR or HIPAA if extensions managing user data, authentication, or access controls are removed, potentially leading to unauthorized access or data breaches.

Mitigation Strategies

Update all miniOrange Joomla extensions to the latest patched versions. Disable or remove unused miniOrange extensions. Monitor Joomla admin access logs for suspicious activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78074. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart