CVE-2021-26040: [20210801] - Core - Insufficient access control for com_media deletion endpoint
Published Aug 24, 2021
·Updated
An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.
Affected Software
1 affected component
Joomla Joomla\!=4.0.0
Event History
Aug 24, 2021
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-26040?
CVE-2021-26040 is a vulnerability in Joomla! 4.0.0 that allows an attacker to delete files without proper permissions.
2
What is the severity of CVE-2021-26040?
CVE-2021-26040 has a severity rating of critical with a score of 9.1.
3
How does CVE-2021-26040 affect Joomla! 4.0.0?
CVE-2021-26040 affects Joomla! 4.0.0 by allowing the media manager to execute file deletion commands without checking user permissions.
4
Is there a fix for CVE-2021-26040?
Yes, it is recommended to update Joomla! to the latest version to fix CVE-2021-26040.
5
Where can I find more information about CVE-2021-26040?
You can find more information about CVE-2021-26040 on the Joomla! security center website.