CVE-2026-78075: Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10
Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - Blog::removeimage() checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image path (src) belonged to that article. On Joomla 3 builds where physical file deletion was triggered, an author could supply their own article ID alongside an arbitrary file path under the /images/ directory to delete arbitrary files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla Extension - joomshaper.com - Helix Ultimateto a version that resolves this vulnerability.Fixed in 2.2.10
Event History
Frequently Asked Questions
Who can exploit this issue?
An author who is authorized to edit an article can exploit the issue by supplying an article ID they may edit together with an arbitrary path under the /images/ directory.
Which deployments are affected by physical file deletion?
The description identifies Joomla 3 builds where physical file deletion was triggered. On those builds, the vulnerable image-removal operation could delete arbitrary files under /images/.
What versions are affected?
Helix Ultimate versions earlier than 2.2.10 are affected.