CVE-2026-77035 MEDIUM

CVE-2026-77035: Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1

Vendor Joomlaeventmanager.net
Product JEM - Joomla Event Manager extension for Joomla
Weakness CWE-639 · IDOR
Published August 27, 2026
Last update August 27, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.

Explanation of Vulnerability in Simple Terms

02Summary

JEM - Joomla Event Manager contains an authorization bypass vulnerability in how it validates user-controlled keys. An authenticated administrator can manipulate request parameters to bypass access controls and modify data they should not have permission to change. The vulnerability requires high-level privileges to exploit and has limited integrity impact.

What an attacker can do

03Attacker Capabilities

Modify event data or settings beyond their authorized scope by manipulating request parameters.

Potential impact on your site

04Site Impact

Administrators with malicious intent or compromised admin accounts can alter event information without proper authorization checks.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the Joomla site.

Key dates

06Disclosure timeline

August 27, 2026 CVE published

Related vulnerabilities

08Related CVE