SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-72531

MEDIUM · CVSS 5.4 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Joomla! versions 4.0.0 to 5.4.7 and 6.0.0 to 6.1.2 are vulnerable due to improper access control checks in custom fields web service endpoints, enabling unauthorized users to create fields for components they should not have access to. This could lead to unauthorized modifications or data exposure within the application. Organizations using affected Joomla! versions should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-72531
Severity
MEDIUM
CVSS
5.4
EPSS
0.19%

Original NVD Description

Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.

Related CVEs

Other vulnerabilities affecting the same vendor(s)