AI analysis
CVE-2026-73371 is an improper access-control (ACL) check in Joomla! core, affecting Joomla 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2. When a user launches a batch operation, the code fails to correctly verify edit permissions on the targeted items, allowing batch copy actions on items the user is not permitted to edit. An attacker must already hold a relatively high-privileged account (CVSS 4.0 rates privileges required as high) and gains only limited impact: they can duplicate otherwise uneditable, potentially restricted content (low confidentiality impact, with no integrity or availability impact). Every Joomla site running any supported 4.x, 5.x (up to 5.4.7) or 6.x (up to 6.1.2) release is affected. There is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts 30-day exploitation probability at just 0.2%, so no exploitation is currently known.
What to do: Upgrade Joomla core to a release newer than 5.4.7 (4.x/5.x line) and newer than 6.1.2 (6.x line) - i.e., apply the core security update published 2026-08-08 or simply the latest available Joomla release. Until patched, review user-group ACL settings and limit batch-operation rights to groups that also hold edit permissions on the relevant content. Given the low CVSS 4.0 score (5.1), high-privilege requirement, and absence of known exploitation, patching can be handled in the normal maintenance cycle.
Affected
| Joomla! (core) | 4.0.0 - 5.4.7 |
| Joomla! (core) | 6.0.0 - 6.1.2 |
Estimated exposure
mass≈1-2 million Joomla sites (all supported 4.x-6.x core releases are in the affected range) — CMS market-share surveys such as W3Techs/BuildWith consistently place Joomla's installed base at over a million live sites, and the affected version ranges cover every currently supported Joomla core branch, though the exploit requires an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.