CVE Field Guide
About Us
CVE-2026-23899
PUBLISHED
Joomla! Core - [20260306] - Improper access check in webservice endpoints
Assigner:
Joomla
Reserved:
17.01.2026
Published:
01.04.2026
Updated:
01.04.2026
An improper access check allows unauthorized access to webservice endpoints.
Metrics
CVSS 4.0
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score:
8.6
CVSS score
8.6
Exploitability Metrics
Vulnerable System Impact Metrics
Subsequent System Impact Metrics
Attack Vector
Network
Confidentiality
High
Confidentiality
None
Attack Complexity
Low
Integrity
High
Integrity
None
Attack Requirements
None
Availability
High
Availability
None
Privileges Required
High
User Interaction
None
CVSS 4.0
Product Status
Vendor
Joomla! Project
Product
Joomla! CMS
Versions
Default:
unaffected
Version 4.0.0-5.4.3 is affected
Version 6.0.0-6.0.3 is affected
Credits
Thành Nguyễn
finder
References
https://developer.joomla.org/security-centre/1032-20260306-core-improper-access-check-in-webservice-endpoints.html
Problem Types
CWE-284 Improper Access Control
CWE
Impacts
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs