AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-71570

MEDIUM · CVSS 5.1

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Joomla Extension from icagenda.com is vulnerable to an ACL bypass that allows unauthorized user enumeration for versions prior to 2.0.0-4.0.11. This flaw enables a backend operator with limited access to enumerate user profiles, potentially exposing sensitive user information. Organizations using this extension should prioritize patching to mitigate the risk of unauthorized access to user data.

CVE
CVE-2026-71570
Severity
MEDIUM
CVSS
5.1
EPSS
N/A

Original NVD Description

Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.