CVE-2026-77034 MEDIUM

CVE-2026-77034: Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1

Vendor Joomlaeventmanager.net
Product JEM - Joomla Event Manager extension for Joomla
Weakness CWE-284
Published August 27, 2026
Last update August 27, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.

Explanation of Vulnerability in Simple Terms

02Summary

JEM - Joomla Event Manager contains an access control flaw that allows unauthenticated attackers to modify event data over the network. The vulnerability affects versions 1.0.0 through 5.0.0. No user interaction is required to exploit this issue. Site administrators should update to a patched version when available.

What an attacker can do

03Attacker Capabilities

Modify event information without authentication.

Potential impact on your site

04Site Impact

Attackers can alter or corrupt event details on your Joomla site without logging in.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

08Related CVE