SB2026081860 - Multiple vulnerabilities in Joomla!



SB2026081860 - Multiple vulnerabilities in Joomla!

Published: August 18, 2026

Security Bulletin ID SB2026081860
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 40% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Arbitrary file upload (CVE-ID: CVE-2026-73373)

CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to unrestricted upload of file with dangerous type in the file upload functionality when uploading SHTML files to a server that executes these files. A remote user can upload a specially crafted SHTML file to execute arbitrary code.

Exploitation depends on the server being configured to execute SHTML files.


2) Improper access control (CVE-ID: CVE-2026-73372)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose contact information from inaccessible contact items.

The vulnerability exists due to improper access control in schema.org contact data handling when generating schema.org snippets. A remote user can access content that injects contact information for inaccessible contact items to disclose contact information from inaccessible contact items.


3) Improper access control (CVE-ID: CVE-2026-73371)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to perform unauthorized copy batch operations on uneditable items.

The vulnerability exists due to improper access control in batch copy actions when handling copy batch requests for uneditable items. A remote user can send a crafted batch copy request to perform unauthorized copy batch operations on uneditable items.


4) Authentication bypass using an alternate path or channel (CVE-ID: CVE-2026-73337)

CWE-ID: CWE-288 - Authentication Bypass Using an Alternate Path or Channel

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass two-factor authentication checks.

The vulnerability exists due to insufficient state checks in the MFA authentication workflow when handling authentication requests. A remote user can manipulate the authentication process to bypass two-factor authentication checks.


5) Cross-site scripting (CVE-ID: CVE-2026-73336)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.

The vulnerability exists due to cross-site scripting in schema.org markup outputs when rendering crafted content. A remote attacker can inject crafted input to execute arbitrary script in a victim's browser.


6) Improper access control (CVE-ID: CVE-2026-72532)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create categories for inaccessible components.

The vulnerability exists due to improper access control in category webservice endpoints when handling category creation requests. A remote user can send a crafted webservice request to create categories for inaccessible components.


7) Improper access control (CVE-ID: CVE-2026-72531)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create fields for inaccessible components.

The vulnerability exists due to improper access control in custom fields webservice endpoints when handling requests to create fields. A remote user can send a specially crafted request to create fields for inaccessible components.


8) Improper access control (CVE-ID: CVE-2026-71574)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass access restrictions and perform unauthorized mutation actions.

The vulnerability exists due to improper access control in webservice endpoints when handling mutation requests. A remote user can send a crafted request to bypass access restrictions and perform unauthorized mutation actions.

The issue affects mutation actions that were restricted in the backend UI.


9) Origin validation error (CVE-ID: CVE-2026-71573)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass cross-origin access restrictions.

The vulnerability exists due to improper access control in CORS origin validation in Joomla! CMS when handling CORS requests. A remote attacker can send a crafted cross-origin request to bypass cross-origin access restrictions.


10) HTTP response splitting (CVE-ID: CVE-2026-71572)

CWE-ID: CWE-113 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause reflected file download and content-type confusion.

The vulnerability exists due to improper output neutralization in multiple download views when handling crafted requests. A remote attacker can send a specially crafted request to cause reflected file download and content-type confusion.


Remediation

Install update from vendor's website.

References