ZeroHour
Joomla Security Centrepublished ()ingested [email protected] (Joomla! Security Strike Team)

[20260805] - Core - Improper ACL checks for category webservice endpoints

mediumAdvisoryimportance 25CVE-2026-72532
AI summary · glm-5.3-flash

Joomla fixes CVE-2026-72532, an improper ACL check letting unauthorized users create categories via webservice endpoints, in CMS 5.4.8/6.1.3.

Joomla disclosed an incorrect access control flaw (CVE-2026-72532) in category webservice endpoints, allowing unauthorized users to create categories for inaccessible components. It affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2 and is rated moderate impact and severity with low probability. The fix ships in Joomla 5.4.8 and 6.1.3 on 2026-08-18; it was reported by Amin Isayev and Geo.

  • CVE-2026-72532 is an incorrect access control flaw in category webservice endpoints
  • Affects Joomla CMS 4.0.0-5.4.7 and 6.0.0-6.1.2
  • Rated moderate severity/impact with low probability of exploitation
  • Patched in Joomla 5.4.8 and 6.1.3 released August 18, 2026
VendorsJoomla
ProductsJoomla CMS

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-72532
Improper ACL checks in Joomla! category webservice endpoints

CVE-2026-72532 is an improper access control (ACL) check in Joomla! Core's webservice (API) endpoints for categories, affecting Joomla 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2. An authenticated API user whose account lacks permission to manage categories can send requests to the category webservice endpoints and create categories anyway; the CVSS vector indicates high required privileges and only low-severity confidentiality and integrity impact. An attacker gains the ability to insert unauthorized categories into the site's content structure, with no availability impact. Any Joomla 4.x, 5.x up to 5.4.7, or 6.x up to 6.1.2 installation is affected, though practical exploitation depends on the webservice API being enabled and reachable. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at about 0.2%, so no exploitation is currently known.

Do: Update Joomla to a release later than 5.4.7 in the 5.4 series or later than 6.1.2 in the 6.1 series, per the 2026-08-06 core advisory; Joomla 4.x sites should upgrade to a supported 5.x release. As an interim mitigation, disable the category/content webservice plugins or restrict external access to the /api endpoints. After patching, review recently created categories for unauthorized changes.

5.1<1%
  • Joomla! Core 4.0.0 through 5.4.7
  • Joomla! Core 6.0.0 through 6.1.2
mass≈1,000,000+ sites running Joomla 4.x–6.1.2 (only the subset with the webservice API plugins enabled is directly exploitable)
Full article

Project: Joomla! SubProject: CMS Impact: Moderate Severity: Moderate Probability: Low Versions: 4.0.0-5.4.7, 6.0.0-6.1.2 Exploit type: Incorrect Access Control Reported Date: 2026-07-15 Fixed Date: 2026-08-18 CVE Number: CVE-2026-72532 Description An improper access check allows unauthorized users to create categories for inaccessible components. Affected Installs Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Amin İsayev, Geo (GitHub.com/geo-chen)

This source does not provide full text. Read it at developer.joomla.org.