CVE-2026-72531
Improper ACL checks for custom fields webservice endpoints
MEDIUM
Joomla CMS
Source officielle
Description
An improper access check allows unauthorized users to create fields for inaccessible components.
Source officielle Description du Joomla Security Centre (Joomla).
Sévérité
5.1
Moyenne · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| Joomla Security Centre | Moderate | — |
| NVD | MEDIUM | 5.1 (v4.0) |
| CERT-FR (ANSSI) | — | — |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- 5.4.8, 6.1.3
- Publiée
- 17/08/2026
- Modifiée
- 03/09/2026
- CWE
- CWE-284
Versions concernées
- 4.0.0 – 5.4.7
- 6.0.0 – 6.1.2
Sources
- Joomla Security Centre Source officielle Avis vu
- NVD CNA Joomla CVE-2026-72531 vu
- CERT-FR (ANSSI) Avis vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Source ajoutée : nvd26/09/2026 09:34 UTC
- Source ajoutée : certfr26/09/2026 09:28 UTC
- Détectée via joomla26/09/2026 09:26 UTC