CVE-2026-23898
Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate
CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
20th
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
| CWE | CWE-73 |
| Vendor | joomla! project |
| Product | joomla! cms |
| Published | Apr 1, 2026 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomla! project joomla! cms
Be the first to know when new unknown vulnerabilities affecting joomla! project joomla! cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Joomla! Project / Joomla! CMS
4.0.0-5.4.3 6.0.0-6.0.3
References
Credits
Phil Taylor