CVE-2021-26038: [20210704] - Core - Privilege escalation through com_installer
Published Jul 7, 2021
·Updated
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in cominstaller lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for cominstaller is limited to super users already.
Affected Software
1 affected component
Joomla Joomla\!>=2.5.0<=3.9.27
Event History
Jul 7, 2021
CVE Published
via MITRE·10:12 AM
Data Sourced
via MITRE·10:12 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-26038.
2
What is the severity of CVE-2021-26038?
The severity of CVE-2021-26038 is high.
3
Which versions of Joomla are affected by CVE-2021-26038?
Joomla versions 2.5.0 through 3.9.27 are affected by CVE-2021-26038.
4
What is the impact of CVE-2021-26038?
CVE-2021-26038 allows privilege escalation through com_installer in Joomla.
5
Is the default system affected by CVE-2021-26038?
No, the default system is not affected by CVE-2021-26038 as the default ACL for com_installer is limited to super users already.