CVE-2021-26038

All FrameworksJoomlaCWE-OtherCVE-2021-26038

CVE-2021-26038

State: PUBLISHED · Published: 2021-07-07 · Updated: 2026-02-25 · Assigner: Joomla
Description
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL checks for superusers. A default system is not affected cause the default ACL for com_installer is limited to super users already.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/26xxx/CVE-2021-26038.json