CVE-2026-92226: Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3
Published Sep 29, 2026
·Updated
Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.
Affected Software
1 affected component
Joomla Joomla Core>=4.0.0<=5.4.8, >=6.0.0<=6.1.3
Event History
Sep 29, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Joomla versions are affected?
The affected ranges are Joomla Core 4.0.0 through 5.4.8 and 6.0.0 through 6.1.3.
2
What access could an attacker gain through this issue?
Unauthorized users may be able to perform web service edit actions on items that should not be editable by them because ACL checks are improper for certain edit tasks.