First published: Wed Jul 07 2021(Updated: )
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | >=2.5.0<=3.9.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-26038.
The severity of CVE-2021-26038 is high.
Joomla versions 2.5.0 through 3.9.27 are affected by CVE-2021-26038.
CVE-2021-26038 allows privilege escalation through com_installer in Joomla.
No, the default system is not affected by CVE-2021-26038 as the default ACL for com_installer is limited to super users already.