First published: Tue Aug 24 2021(Updated: )
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
Credit: security@joomla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Joomla\! | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26040 is a vulnerability in Joomla! 4.0.0 that allows an attacker to delete files without proper permissions.
CVE-2021-26040 has a severity rating of critical with a score of 9.1.
CVE-2021-26040 affects Joomla! 4.0.0 by allowing the media manager to execute file deletion commands without checking user permissions.
Yes, it is recommended to update Joomla! to the latest version to fix CVE-2021-26040.
You can find more information about CVE-2021-26040 on the Joomla! security center website.