CVE-2026-78074
nicheUnauthenticated arbitrary extension deletion in free miniOrange Joomla extensions
Several free extensions for Joomla from miniOrange contain a missing authentication check (CWE-284) that allows an unauthenticated remote attacker to trigger deinstallation of arbitrary installed extensions. The flaw is triggered by sending crafted requests to the affected endpoint without any login or privileges. An attacker gains the ability to delete any extension on the site, which can break site functionality and login/SSO flows (high integrity and availability impact per the CVSS 4.0 vector), though the flaw does not by itself permit code execution or data theft. Only the free versions of the miniOrange Joomla plugins are affected; paid versions are not. Exploitation status is calm: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Joomla administrators running free miniOrange extensions should inventory which of these plugins are installed and check miniOrange's Joomla extension pages or advisories for patched releases, then upgrade promptly once fixed versions are published (no fixed version numbers are available in the source data). Because the bug allows unauthenticated deletion of arbitrary extensions, verify after updating that expected extensions (especially login/SSO components) are still installed. Until patched, consider limiting unauthenticated access to the Joomla administrative endpoints used by these plugins as an interim mitigation.
| miniOrange extensions for Joomla (multiple plugins) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.
- Ecosystems
- Joomla
- Weakness
- CWE-284
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.