Improper access control in Joomla! - CVE-2026-71574
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to bypass access restrictions and perform unauthorized mutation actions.
The vulnerability exists due to improper access control in webservice endpoints when handling mutation requests. A remote user can send a crafted request to bypass access restrictions and perform unauthorized mutation actions.
The issue affects mutation actions that were restricted in the backend UI.