Understanding the Joomla! Core Inconsistent ACL Checks Vulnerability (CVE-2026-71574)
A notable security flaw has been identified in Joomla! Core, affecting several versions of the popular content management system. This vulnerability, tracked as CVE-2026-71574, involves inconsistent access control list (ACL) checks within the webservice endpoints. Essentially, this means that some actions that should have been restricted to authorized users were not properly checked when performed through Joomla!’s webservice, even though these same actions were correctly blocked in the standard backend user interface.
This inconsistency could allow unauthorized individuals to make changes or perform “mutation actions” that they shouldn’t be able to, potentially compromising the integrity of your Joomla! website. While the severity is rated as medium, it’s crucial for administrators and developers to address this issue promptly to maintain site security.
CVE Details
- Product: Joomla! Core
- Published: August 18, 2026
- Severity: Medium (CVSS Score 6.5)
- Status: Analyzed
Affected Products
The vulnerability impacts Joomla! CMS installations running the following versions:
- Joomla! versions 4.0.0 through 5.4.7
- Joomla! versions 6.0.0 through 6.1.2
If your website is running any of these versions, it is highly recommended to take action as soon as possible.
Current Status
The vulnerability, CVE-2026-71574, has been thoroughly analyzed. The Joomla! project team has investigated the issue and released fixes to address the inconsistent ACL checks.
Severity Level
This vulnerability carries a Medium severity rating, with a CVSS score of 6.5. A medium severity indicates that while the vulnerability could allow unauthorized actions, it might require specific conditions to be exploited or may not lead to immediate, widespread catastrophic impact. However, the potential for unauthorized data manipulation or other sensitive operations through webservice endpoints makes this a significant concern that demands attention.
Possible Solutions
The good news is that Joomla! has released updates to fix this security flaw. To protect your website from this vulnerability, you should upgrade your Joomla! installation to a patched version immediately.
- For Joomla! 5.x series, upgrade to version 5.4.8.
- For Joomla! 6.x series, upgrade to version 6.1.3.
Regularly updating your CMS is one of the most effective ways to secure your website against known vulnerabilities. Always back up your site before performing any updates.
References
https://developer.joomla.org/security-centre/1070-20260803-core-inconsistent-acl-checks-for-mutating-webservice-endpoints.html
https://www.joomla.org/


