ZeroHour
Joomla Security Centrepublished ()ingested [email protected] (Joomla! Security Strike Team)

[20260804] - Core - Improper ACL checks for custom fields webservice endpoints

mediumAdvisoryimportance 22CVE-2026-72531
AI summary · glm-5.3-flash

Joomla patches CVE-2026-72531, an improper ACL check allowing unauthorized custom-field creation via webservice endpoints, in CMS 5.4.8/6.1.3.

Joomla disclosed an incorrect access control issue (CVE-2026-72531) letting unauthorized users create custom fields for inaccessible components through webservice endpoints. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2, rated moderate impact and severity with low probability. Fixed in Joomla 5.4.8 and 6.1.3; reported by ebadfd on 2026-07-06.

  • CVE-2026-72531 allows unauthorized custom-field creation via webservice endpoints
  • Affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2
  • Fix shipped in Joomla 5.4.8 and 6.1.3
VendorsJoomla
ProductsJoomla CMS

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-72531
Improper ACL checks in Joomla! core custom fields web service endpoints

CVE-2026-72531 is an improper access control flaw (CWE-284) in the Joomla! CMS core, affecting the custom fields REST API (web service) endpoints. It is triggered when an authenticated, privileged user sends requests to these network-accessible API endpoints for a component they do not have permission to access, bypassing the ACL checks. The attacker can create custom fields on components that should be off-limits to them, a low-severity confidentiality and integrity issue scored 5.1 (medium) under CVSS 4.0. Any site running Joomla 4.0.0 through 5.4.7 or 6.0.0 through 6.1.2 is affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2%, so no exploitation is currently known.

Do: Upgrade Joomla! to a release beyond the affected ranges — at minimum 5.4.8 for the 5.x branch or 6.1.3 for the 6.x branch, or the latest available. As an interim mitigation, disable the Web Services – Custom Fields plugin or restrict API access until patched. After patching, review custom fields on restricted components to confirm no unauthorized fields were created.

5.1<1%
  • Joomla! CMS 4.0.0 through 5.4.7
  • Joomla! CMS 6.0.0 through 6.1.2
mass≈1 million sites (Joomla powers roughly 1–2 million live websites, most now on the affected 4.x–6.x branches)
Full article

Project: Joomla! SubProject: CMS Impact: Moderate Severity: Moderate Probability: Low Versions: 4.0.0-5.4.7, 6.0.0-6.1.2 Exploit type: Incorrect Access Control Reported Date: 2026-07-06 Fixed Date: 2026-08-18 CVE Number: CVE-2026-72531 Description An improper access check allows unauthorized users to create fields for inaccessible components. Affected Installs Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: ebadfd

This source does not provide full text. Read it at developer.joomla.org.