What is CVE-2026-72531?
CVE-2026-72531 is a vulnerability in Joomla! Core affecting versions 4.0.0-5.4.7 and 6.0.0-6.1.2. Improper ACL checks in custom fields webservice endpoints allow unauthorized users to create fields for inaccessible components. It is recommended to update Joomla to the latest version.
Azərbaycanca: CVE-2026-72531, Joomla! Core-u təsir edən boşluqdur. 4.0.0-5.4.7 və 6.0.0-6.1.2 versiyalarında custom fields webservice endpoint-lərində düzgün olmayan ACL yoxlaması səbəbindən icazəsiz istifadəçilərə əlçatmaz komponentlər üçün fields yaratmağa imkan verir. Joomla-nı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Joomla! are affected by CVE-2026-72531?
This vulnerability affects Joomla! Core versions from 4.0.0 through 5.4.7 and from 6.0.0 through 6.1.2.
How to mitigate the CVE-2026-72531 vulnerability?
To mitigate the vulnerability, it is recommended to update Joomla! to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.