CVE-2026-21629

All FrameworksJoomlaCWE-284CVE-2026-21629

CVE-2026-21629

State: PUBLISHED · Published: 2026-04-01 · Updated: 2026-04-01 · Assigner: Joomla
Description
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2026/21xxx/CVE-2026-21629.json