ZeroHour
Joomla Security Centrepublished ()ingested [email protected] (Joomla! Security Strike Team)

[20260808] - Core - Improper ACL checks for batch copy actions

lowAdvisoryimportance 24CVE-2026-73371
AI summary · glm-5.3-flash

Joomla fixed CVE-2026-73371, an improper ACL check letting unauthorized users batch-copy uneditable items in Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260808 describes CVE-2026-73371, an incorrect access control issue in batch copy actions. The flaw allows unauthorized users to perform copy batch operations on items they cannot edit. Affected versions are 4.0.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Sabuhi Mammadov on 2026-07-28.

  • Unauthorized users could batch-copy uneditable items
  • Affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2
  • Fixed in Joomla 5.4.8 and 6.1.3
VendorsJoomla
ProductsJoomla CMS
OrganizationsJoomla

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73371
Improper ACL check enables unauthorized batch copy in Joomla! core

CVE-2026-73371 is an improper access-control (ACL) check in Joomla! core, affecting Joomla 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2. When a user launches a batch operation, the code fails to correctly verify edit permissions on the targeted items, allowing batch copy actions on items the user is not permitted to edit. An attacker must already hold a relatively high-privileged account (CVSS 4.0 rates privileges required as high) and gains only limited impact: they can duplicate otherwise uneditable, potentially restricted content (low confidentiality impact, with no integrity or availability impact). Every Joomla site running any supported 4.x, 5.x (up to 5.4.7) or 6.x (up to 6.1.2) release is affected. There is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS puts 30-day exploitation probability at just 0.2%, so no exploitation is currently known.

Do: Upgrade Joomla core to a release newer than 5.4.7 (4.x/5.x line) and newer than 6.1.2 (6.x line) - i.e., apply the core security update published 2026-08-08 or simply the latest available Joomla release. Until patched, review user-group ACL settings and limit batch-operation rights to groups that also hold edit permissions on the relevant content. Given the low CVSS 4.0 score (5.1), high-privilege requirement, and absence of known exploitation, patching can be handled in the normal maintenance cycle.

5.1<1%
  • Joomla! (core) 4.0.0 - 5.4.7
  • Joomla! (core) 6.0.0 - 6.1.2
mass≈1-2 million Joomla sites (all supported 4.x-6.x core releases are in the affected range)
Full article

Project: Joomla! SubProject: CMS Impact: Low Severity: Low Probability: Low Versions: 4.0.0-5.4.7,6.0.0-6.1.2 Exploit type: Incorrect Access Control Reported Date: 2026-07-28 Fixed Date: 2026-08-18 CVE Number: CVE-2026-73371 Description An improper access check allows unauthorized users to perform copy batch operations on uneditable items. Affected Installs Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Sabuhi Mammadov

This source does not provide full text. Read it at developer.joomla.org.