CVE-2026-71574

Vulnérabilités

CVE-2026-71574

Inconsistent ACL checks for mutating webservice endpoints

HIGH Joomla CMS Source officielle

An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

Source officielle Description du Joomla Security Centre (Joomla).

8.5 Élevée · CVSS 4.0

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Score retenu : NVD

SourceSévérité d'origineCVSS
Joomla Security CentreModerate —
NVDHIGH 8.5 (v4.0)
CERT-FR (ANSSI)— —
Produit
Joomla CMS
Corrigée dans
5.4.8, 6.1.3
Publiée
17/08/2026
Modifiée
03/09/2026
CWE
CWE-284
  • 4.0.0 – 5.4.7
  • 6.0.0 – 6.1.2
  • Joomla Security Centre Source officielle Avis vu
  • NVD CNA Joomla CVE-2026-71574 vu
  • CERT-FR (ANSSI) Avis vu

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Source ajoutée : nvd26/09/2026 09:34 UTC
  2. Source ajoutée : certfr26/09/2026 09:28 UTC
  3. Détectée via joomla26/09/2026 09:26 UTC