ZeroHour

CVE-2026-73371

mass

Improper ACL check enables unauthorized batch copy in Joomla! core

CVSS 4.0
5.1 medium
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-73371 is an improper access-control (ACL) check in Joomla! core, affecting Joomla 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2. When a user launches a batch operation, the code fails to correctly verify edit permissions on the targeted items, allowing batch copy actions on items the user is not permitted to edit. An attacker must already hold a relatively high-privileged account (CVSS 4.0 rates privileges required as high) and gains only limited impact: they can duplicate otherwise uneditable, potentially restricted content (low confidentiality impact, with no integrity or availability impact). Every Joomla site running any supported 4.x, 5.x (up to 5.4.7) or 6.x (up to 6.1.2) release is affected. There is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts 30-day exploitation probability at just 0.2%, so no exploitation is currently known.

What to do: Upgrade Joomla core to a release newer than 5.4.7 (4.x/5.x line) and newer than 6.1.2 (6.x line) - i.e., apply the core security update published 2026-08-08 or simply the latest available Joomla release. Until patched, review user-group ACL settings and limit batch-operation rights to groups that also hold edit permissions on the relevant content. Given the low CVSS 4.0 score (5.1), high-privilege requirement, and absence of known exploitation, patching can be handled in the normal maintenance cycle.

Affected
Joomla! (core)4.0.0 - 5.4.7
Joomla! (core)6.0.0 - 6.1.2
Estimated exposure
mass≈1-2 million Joomla sites (all supported 4.x-6.x core releases are in the affected range) — CMS market-share surveys such as W3Techs/BuildWith consistently place Joomla's installed base at over a million live sites, and the affected version ranges cover every currently supported Joomla core branch, though the exploit requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

[20260808] - Core - Improper ACL checks for batch copy actions

Joomla fixed CVE-2026-73371, an improper ACL check letting unauthorized users batch-copy uneditable items in Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260808 describes CVE-2026-73371, an incorrect access control issue in batch copy actions. The flaw allows unauthorized users to perform copy batch operations on items they cannot edit. Affected versions are 4.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Sabuhi Mammadov on 2026-07-28.

Joomla Security Centre · 29d agoAdvisoryCVE-2026-73371