[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints
Joomla fixes CVE-2026-71574, inconsistent ACL checks letting unauthorized users mutate data via webservice APIs, in CMS 5.4.8/6.1.3.
Joomla disclosed an inconsistent access control flaw (CVE-2026-71574) in mutating webservice endpoints, where unauthorized users could perform mutations restricted in the backend UI; impact is rated high. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2, with moderate severity and low probability. The fix ships in Joomla 5.4.8 and 6.1.3 on 2026-08-18.
- CVE-2026-71574 lets unauthorized users perform mutations via webservice endpoints
- API mutations bypassed backend UI ACL restrictions; impact rated high
- Affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2
- Patched in Joomla 5.4.8 and 6.1.3
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71574 | Inconsistent ACL checks in Joomla! webservice API allow unauthorized mutations CVE-2026-71574 is an improper access control flaw (CWE-284) in the Joomla! CMS core, affecting versions 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2, in which the webservice (REST API) endpoints enforce weaker ACL checks than the backend administration UI. An attacker holding credentials for an account with API access can send create, update, or delete requests to webservice endpoints and have them succeed even though the same mutations would be denied for that account in the backend; the CVSS 4.0 vector scores it as network-exploitable, low complexity, requiring high-privileged credentials and no user interaction. The impact is unauthorized modification of site data through the API without the required permissions, with the CVSS vector rating high impact to confidentiality and integrity and no availability impact. Any Joomla installation on the affected versions with the webservice plugins enabled and API users configured is exposed. No public proof-of-concept, no CISA KEV listing, and a low EPSS score of 0.2% indicate exploitation has not yet been observed. Do: Update Joomla installs in the 4.x/5.x line beyond 5.4.7 and in the 6.x line beyond 6.1.2 using the patched core releases published on 2026-08-03. Until patched, disable unneeded webservice plugins and restrict which API users/credentials can reach the /api endpoints, and review change logs for content mutations made by accounts lacking the corresponding backend permissions. | 8.5 | <1% |
| mass≈1M+ sites (essentially the entire Joomla 4.x–6.x installed base; the web-services-enabled subset likely in the hundreds of thousands) |
Project: Joomla! SubProject: CMS Impact: High Severity: Moderate Probability: Low Versions: 4.0.0-5.4.7, 6.0.0-6.1.2 Exploit type: Incorrect Access Control Reported Date: 2026-07-15 Fixed Date: 2026-08-18 CVE Number: CVE-2026-71574 Description An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI. Affected Installs Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Paul, Sorrachat, tms, Morris Baumgarten-Egemole
This source does not provide full text. Read it at developer.joomla.org.