What is CVE-2026-75114?
CVE-2026-75114 is an open redirect vulnerability in the Zoo Joomla extension before version 4.1.64, found in the `CommentController::twitterAuthenticate()` function. The flaw occurs because the `referer` request parameter is passed directly to `setRedirect()` without any validation, potentially allowing attackers to redirect users to malicious websites. To mitigate this, updating the Zoo extension to version 4.1.64 or later is strongly recommended.
Azərbaycanca: CVE-2026-75114, Zoo Joomla genişlənməsinin 4.1.64-dən əvvəlki versiyalarında `CommentController::twitterAuthenticate()` funksiyasında aşkarlanmış açıq yönləndirmə zəifliyidir. Bu, `referer` parametrinin heç bir yoxlamadan keçmədən birbaşa `setRedirect()` metoduna ötürülməsi səbəbindən baş verir və istifadəçiləri zərərli saytlara yönləndirmək üçün istismar edilə bilər. Bu zəiflikdən qorunmaq üçün Zoo genişlənməsini ən azı 4.1.64 versiyasına yeniləmək tövsiyə olunur.
FAQ2
In which function of the Zoo Joomla extension was CVE-2026-75114 discovered?
This vulnerability was discovered in the `CommentController::twitterAuthenticate()` function.
To which version should the Zoo extension be updated to mitigate CVE-2026-75114?
It is recommended to update the Zoo extension to version 4.1.64 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.