CVE-2026-72531: Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2
Published Aug 18, 2026
·Updated
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
Affected Software
1 affected component
Joomla Joomla! Core>=4.0.0<5.4.7, >=6.0.0<=6.1.2
Event History
Aug 18, 2026
CVE Published
via MITRE·04:08 PM
Data Sourced
via MITRE·04:08 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Joomla! Core versions are affected?
Joomla! Core installations running versions 4.0.0 through 5.4.7 or 6.0.0 through 6.1.2 are affected.
2
What could an attacker do?
An unauthorized user can create custom fields for components they are not permitted to access through the custom-fields webservice endpoints. The provided information does not specify any additional authentication or privilege requirement.