CVE-2026-21629
Description
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
CWE
- CWE-284 — CWE-284 Improper Access Control
Affected
- Joomla! Project / Joomla! CMS — v=3.0.0-5.4.3 [affected]; v=6.0.0-6.0.3 [affected]
CVSS
- 4.0 score=6.3 severity=MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
References
- https://developer.joomla.org/security-centre/1027-20260301-core-acl-hardening-in-com-ajax.html vendor-advisory
Source
cvelistV5-main/cves/2026/21xxx/CVE-2026-21629.json