ZeroHour

CVE-2026-71573

mass

Unauthenticated CORS origin validation bypass in Joomla! Core 4.x–6.x

CVSS 4.0
6.9 medium
EPSS
<1%p16
Published
()
Modified
AI analysis

Joomla! Core fails to properly validate the origins configured as allowed for cross-origin (CORS) requests, so CORS requests coming from origins that are not on the site's allow-list are accepted as valid. It is triggered whenever a browser sends a CORS request to an affected Joomla site that has CORS origins configured; because the origin check is broken, a page on an attacker-controlled origin can have a visitor's browser issue cross-origin requests to the Joomla site and have the responses treated as readable in the visitor's session context. What the attacker gains is limited but real cross-origin access — the ability to read or interact with responses from affected endpoints using the visitor's credentials — which the CVSS 4.0 score (6.9, Medium, low impact on the subsequent system) reflects. Anyone running Joomla 4.0.0 through 5.4.7 or 6.0.0 through 6.1.2 is within the affected ranges, although only sites where administrators have actually configured CORS origins are practically exposed. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.2% probability of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Upgrade to the latest patched release — at least Joomla 5.4.8 (for 4.x/5.x sites) or 6.1.3 (for 6.x sites), or later. In the meantime, review which origins your site's CORS configuration allows and, if you do not rely on cross-origin access to Joomla endpoints, restrict or temporarily disable it. After patching, confirm that any third-party origins that legitimately depend on CORS access to your site still work as expected.

Affected
Joomla! (Core)4.0.0 – 5.4.7
Joomla! (Core)6.0.0 – 6.1.2
Estimated exposure
mass≈300,000+ Joomla sites fall in the affected version ranges (order of magnitude 10^5–10^6); practical exposure is lower since only CORS-configured sites are… — Joomla's share of websites with a known CMS (roughly 2% per W3Techs) and Joomla's own active-install statistics imply a live install base of hundreds of thousands, and nearly every 4.x/5.x release below 5.4.8 plus all 6.x releases below…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-93
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

[20260802] - Core - Improper CORS origin validation

Joomla patches CVE-2026-71573, improper CORS origin validation in CMS requests, in versions 5.4.8 and 6.1.3.

Joomla disclosed improper CORS origin validation (CVE-2026-71573), where configured CORS origins were not properly validated on CORS requests, rated moderate impact/severity and moderate probability. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2. Fixed in Joomla 5.4.8 and 6.1.3; reported on 2026-07-09 by Agamemnon Fakas and caveeroo.

Joomla Security Centre · 29d agoAdvisoryCVE-2026-71573