CVE-2026-49049 PUBLISHED

Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler

Assigner: Joomla
Reserved: 27.05.2026 Published: 29.06.2026 Updated: 29.06.2026

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Product Status

Vendor joomshaper.com
Product Helix3 extension for Joomla
Versions Default: unaffected
  • Version 1.0-3.1.1 is affected

Credits

  • Phil Taylor finder

References

Problem Types

  • CWE-284 Improper Access Control CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs