ZeroHour
Joomla Security Centrepublished ()ingested [email protected] (Joomla! Security Strike Team)

[20260802] - Core - Improper CORS origin validation

mediumAdvisoryimportance 28CVE-2026-71573
AI summary · glm-5.3-flash

Joomla patches CVE-2026-71573, improper CORS origin validation in CMS requests, in versions 5.4.8 and 6.1.3.

Joomla disclosed improper CORS origin validation (CVE-2026-71573), where configured CORS origins were not properly validated on CORS requests, rated moderate impact/severity and moderate probability. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2. Fixed in Joomla 5.4.8 and 6.1.3; reported on 2026-07-09 by Agamemnon Fakas and caveeroo.

  • CVE-2026-71573 is improper CORS origin validation in Joomla CMS
  • Affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2
  • Fix available in Joomla 5.4.8 and 6.1.3
VendorsJoomla
ProductsJoomla CMS

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-71573
Unauthenticated CORS origin validation bypass in Joomla! Core 4.x–6.x

Joomla! Core fails to properly validate the origins configured as allowed for cross-origin (CORS) requests, so CORS requests coming from origins that are not on the site's allow-list are accepted as valid. It is triggered whenever a browser sends a CORS request to an affected Joomla site that has CORS origins configured; because the origin check is broken, a page on an attacker-controlled origin can have a visitor's browser issue cross-origin requests to the Joomla site and have the responses treated as readable in the visitor's session context. What the attacker gains is limited but real cross-origin access — the ability to read or interact with responses from affected endpoints using the visitor's credentials — which the CVSS 4.0 score (6.9, Medium, low impact on the subsequent system) reflects. Anyone running Joomla 4.0.0 through 5.4.7 or 6.0.0 through 6.1.2 is within the affected ranges, although only sites where administrators have actually configured CORS origins are practically exposed. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.2% probability of exploitation in the next 30 days, so no exploitation is currently known.

Do: Upgrade to the latest patched release — at least Joomla 5.4.8 (for 4.x/5.x sites) or 6.1.3 (for 6.x sites), or later. In the meantime, review which origins your site's CORS configuration allows and, if you do not rely on cross-origin access to Joomla endpoints, restrict or temporarily disable it. After patching, confirm that any third-party origins that legitimately depend on CORS access to your site still work as expected.

6.9<1%
  • Joomla! (Core) 4.0.0 – 5.4.7
  • Joomla! (Core) 6.0.0 – 6.1.2
mass≈300,000+ Joomla sites fall in the affected version ranges (order of magnitude 10^5–10^6); practical exposure is lower since only CORS-configured sites are…
Full article

Project: Joomla! SubProject: CMS Impact: Moderate Severity: Moderate Probability: Moderate Versions: 4.0.0-5.4.7, 6.0.0-6.1.2 Exploit type: Improper CORS Origin Validation Reported Date: 2026-07-09 Fixed Date: 2026-08-18 CVE Number: CVE-2026-71573 Description An improper implementation prevented configured CORS origins from being properly validated in CORS requests. Affected Installs Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Agamemnon Fakas, caveeroo

This source does not provide full text. Read it at developer.joomla.org.