CVE-2026-35223: Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
Published May 26, 2026
·Updated
An improper access check allows unauthorized access to comconfig webservice endpoints.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=4.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35223?
The severity of CVE-2026-35223 is rated high with a score of 8.6.
2
How do I fix CVE-2026-35223?
To fix CVE-2026-35223, ensure that you update to the latest version of Joomla that includes the security patch.
3
What type of vulnerability is CVE-2026-35223?
CVE-2026-35223 is categorized as an improper access check vulnerability in Joomla's com_config webservice endpoints.
4
Who is affected by CVE-2026-35223?
All versions of Joomla that include the com_config webservice endpoints are potentially affected by CVE-2026-35223.
5
What is the impact of CVE-2026-35223?
The impact of CVE-2026-35223 allows unauthorized access to configuration settings, which could lead to further exploitation.