CVE-2026-78074: Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions
Published Aug 31, 2026
·Updated
Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected.
Affected Software
1 affected component
Joomla! miniOrange extensions (free versions)=
Event History
Aug 31, 2026
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
DescriptionWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects free versions of miniOrange extensions for Joomla!. The provided information does not identify specific extension names or versions.
2
What access does an attacker need to exploit this?
No authentication is required. An unauthenticated actor can delete arbitrary extensions that are installed on the Joomla! site.
3
Are paid miniOrange plugin versions affected?
The issue is described as affecting only the free versions of the miniOrange plugins.