🔐 CVE Alert

CVE-2026-72532

UNKNOWN 0.0

Joomla! Core - [20260805] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.

CWE CWE-284
Vendor joomla! project
Product joomla! cms
Published Aug 18, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for joomla! project joomla! cms

Be the first to know when new unknown vulnerabilities affecting joomla! project joomla! cms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Joomla! Project / Joomla! CMS
4.0.0-5.4.6 6.0.0-6.1.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
joomla.org: https://www.joomla.org/ developer.joomla.org: https://developer.joomla.org/security-centre/1072-20260805-core-improper-acl-checks-for-category-webservice-endpoints.html

Credits

Amin İsayev Geo | GitHub.com/geo-chen