Joomla! Core - [20260913] - Core - Improper ACL checks for varous webservice edit tasks in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.
An improper access check allows unauthorized access to comconfig webservice endpoints.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
An improper access check allows privilege escalation through the comusers batch task.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
An improper access check allows privelege escalation through the comusers group editing webservice endpoint.
An improper access check allows unauthorized access to webservice endpoints.