ZeroHour

CVE-2026-78074

niche

Unauthenticated arbitrary extension deletion in free miniOrange Joomla extensions

CVSS 4.0
8.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

Several free extensions for Joomla from miniOrange contain a missing authentication check (CWE-284) that allows an unauthenticated remote attacker to trigger deinstallation of arbitrary installed extensions. The flaw is triggered by sending crafted requests to the affected endpoint without any login or privileges. An attacker gains the ability to delete any extension on the site, which can break site functionality and login/SSO flows (high integrity and availability impact per the CVSS 4.0 vector), though the flaw does not by itself permit code execution or data theft. Only the free versions of the miniOrange Joomla plugins are affected; paid versions are not. Exploitation status is calm: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Joomla administrators running free miniOrange extensions should inventory which of these plugins are installed and check miniOrange's Joomla extension pages or advisories for patched releases, then upgrade promptly once fixed versions are published (no fixed version numbers are available in the source data). Because the bug allows unauthenticated deletion of arbitrary extensions, verify after updating that expected extensions (especially login/SSO components) are still installed. Until patched, consider limiting unauthenticated access to the Joomla administrative endpoints used by these plugins as an interim mitigation.

Affected
miniOrange extensions for Joomla (multiple plugins)
Estimated exposure
nichelikely on the order of thousands of sites worldwide (est.; free-version Joomla plugins with no install counts provided) — No per-plugin install counts were supplied, so this is an estimate based on typical Joomla Extensions Directory install counts for free miniOrange Joomla plugins, which are generally in the low thousands per extension; only free versions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.

Ecosystems
Joomla
Weakness
CWE-284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.