CVE-2026-71574: Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla!to a version that resolves this vulnerability.Fixed in 4.0.0-5.4.7 - Upgrade
Upgrade
Joomla!to a version that resolves this vulnerability.Fixed in 6.0.0-6.1.2
Event History
Frequently Asked Questions
Which Joomla release lines should be considered affected?
Joomla! Core versions 4.0.0 through 5.4.7 and 6.0.0 through 6.1.2 are identified as affected.
Are backend UI permission restrictions sufficient to protect the affected actions?
No. The issue exists because access controls for mutation actions can differ between webservice endpoints and the backend UI; an action restricted in the UI may be permitted through a webservice endpoint.