SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77035

MEDIUM · CVSS 5.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Joomla Event Manager extension prior to version 5.0.1 is vulnerable to cross-user event and venue takeover, allowing a registered user with edit-own rights to manipulate form fields and gain unauthorized access to another user's records. This could lead to unauthorized modifications or control over events, posing a risk to event integrity and user data. Joomla site administrators and developers using this extension should prioritize applying the latest update to mitigate this vulnerability.

CVE
CVE-2026-77035
Severity
MEDIUM
CVSS
5.1
EPSS
0.23%

Original NVD Description

Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.