CVE-2026-71570: Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11
Published Aug 14, 2026
·Updated
Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to comicagenda only could enumerate Joomla user profiles.
Affected Software
1 affected component
joomla-extension/icagenda.com<4.0.11
Event History
Aug 14, 2026
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-71570?
CVE-2026-71570 has a risk score of 23, indicating a significant vulnerability.
2
What does CVE-2026-71570 exploit?
CVE-2026-71570 exploits an ACL bypass vulnerability that allows arbitrary user enumeration.
3
Who is affected by CVE-2026-71570?
Users of the icagenda extension for Joomla versions prior to 2.0.0-4.0.11 are affected by CVE-2026-71570.
4
How do I fix CVE-2026-71570?
To fix CVE-2026-71570, upgrade the icagenda extension to version 2.0.0-4.0.11 or later.
5
What is the impact of CVE-2026-71570?
The impact of CVE-2026-71570 is that unauthorized users can enumerate Joomla user profiles, potentially disclosing sensitive information.