What the vulnerability does
01Description
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Explanation of Vulnerability in Simple Terms
02Summary
Joomla! CMS versions 4.0.0 through 5.4.6 contain an access control flaw that allows high-privilege users to gain unauthorized access to sensitive functionality or data. The vulnerability requires administrative or elevated account credentials to exploit. Site administrators should update to a version newer than 5.4.6 when available.
What an attacker can do
03Attacker Capabilities
A high-privilege user can access functionality or data they should not have permission to view or modify.
Potential impact on your site
04Site Impact
Privileged user accounts (admins, super-users) could be compromised to access restricted site data or settings.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative or privileged account credentials on the Joomla site.
Key dates
06Disclosure timeline
August 18, 2026
CVE published
August 18, 2026
Record updated