CVE-2026-77990 MEDIUM

CVE-2026-77990: Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1

Vendor Joomlaeventmanager.net
Product JEM - Joomla Event Manager extension for Joomla
Weakness CWE-639 · IDOR
Published August 27, 2026
Last update August 27, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.

Explanation of Vulnerability in Simple Terms

02Summary

JEM - Joomla Event Manager contains an authorization bypass vulnerability in how it validates user-controlled keys. An authenticated user with low privileges can bypass access controls by manipulating request parameters, potentially gaining unauthorized access to restricted event data or functionality. The vulnerability requires an active Joomla user account but no additional user interaction.

What an attacker can do

03Attacker Capabilities

Bypass access controls to view or modify event data they should not have permission to access.

Potential impact on your site

04Site Impact

Unauthorized users may access or modify event information, compromising event privacy and data integrity.

Conditions required to exploit

05Prerequisites

Attacker must have a valid Joomla user account with low privileges; no special network access required.

Key dates

06Disclosure timeline

August 27, 2026 CVE published

Related vulnerabilities

08Related CVE