What is CVE-2026-71570?
CVE-2026-71570 is an ACL bypass vulnerability in the Joomla icagenda.com extension allowing arbitrary user enumeration. A backend operator with access scoped only to 'com_icagenda' can enumerate Joomla user profiles. Affected versions below 2.0.0-4 must be updated immediately.
Azərbaycanca: CVE-2026-71570 Joomla-nın icagenda.com komponentində AİS-i keçərək ixtiyari istifadəçi məlumatlarının əldə edilməsinə imkan verən boşluqdur. Yalnız 'com_icagenda' ilə məhdudlaşdırılmış backend operator Joomla istifadəçi profillərini sadalaya bilər. 2.0.0-4 versiyasından əvvəlkilər təsirlənir, dərhal yenilənməlidir.
Related CVEs
link basis: shared vendors: Joomla, icagenda.com
FAQ2
Which Joomla component is affected by CVE-2026-71570?
This vulnerability affects the Joomla icagenda.com component.
What type of privileged user can bypass the ACL restriction in CVE-2026-71570?
A backend operator with access scoped only to 'com_icagenda' can bypass the ACL restriction.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.