CVE-2026-40384: Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint
An improper validation of the search parameter of the commedia files API endpoint leads to a path traversal vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-40384?
CVE-2026-40384 is a medium severity path traversal vulnerability in the com_media webservice endpoint of Joomla that allows unauthorized file access.
What causes the vulnerability CVE-2026-40384?
CVE-2026-40384 is caused by improper validation of the search parameter in the com_media files API endpoint.
How do I fix CVE-2026-40384?
To fix CVE-2026-40384, update your Joomla installation to a patched version that protects against the path traversal exploitation.
What is the impact of CVE-2026-40384?
The impact of CVE-2026-40384 includes potential unauthorized access to sensitive files on the server due to path traversal.
How can I determine if my site is affected by CVE-2026-40384?
To determine if your site is affected by CVE-2026-40384, check if it is running a vulnerable version of Joomla with the com_media webservice endpoint.