What is CVE-2026-67366?
This CVE describes a CSRF vulnerability in the frontend registration actions of the iCagenda extension for Joomla, affecting versions prior to 2.0.0-4.0.11. Multiple state-changing operations are callable without a CSRF token check, potentially allowing unauthorized actions on behalf of authenticated users. Updating the iCagenda extension to the latest version is recommended to mitigate this issue.
Azərbaycanca: Bu CVE, Joomla üçün iCagenda genişləndirməsinin 2.0.0-4.0.11-dən əvvəlki versiyalarında frontend qeydiyyat əməliyyatlarında CSRF (Cross-Site Request Forgery) zəifliyini təsvir edir. Təsirə məruz qalan əməliyyatlar CSRF token yoxlanışı olmadan çağırıla bilər, bu da istifadəçilərin xəbəri olmadan vəziyyət dəyişdirən hərəkətlərin icrasına səbəb ola bilər. Bu problemi həll etmək üçün iCagenda genişləndirməsini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of the iCagenda extension are affected by CVE-2026-67366?
This vulnerability affects versions of the iCagenda extension prior to 2.0.0-4.0.11.
What is the most effective way to mitigate CVE-2026-67366?
Updating the iCagenda extension to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.