Joomla! Core Inconsistent ACL Checks Vulnerability (CVE-2026-71574) — Medium Severity

Understanding the Joomla! Core Inconsistent ACL Checks Vulnerability (CVE-2026-71574)

A notable security flaw has been identified in Joomla! Core, affecting several versions of the popular content management system. This vulnerability, tracked as CVE-2026-71574, involves inconsistent access control list (ACL) checks within the webservice endpoints. Essentially, this means that some actions that should have been restricted to authorized users were not properly checked when performed through Joomla!’s webservice, even though these same actions were correctly blocked in the standard backend user interface.

This inconsistency could allow unauthorized individuals to make changes or perform “mutation actions” that they shouldn’t be able to, potentially compromising the integrity of your Joomla! website. While the severity is rated as medium, it’s crucial for administrators and developers to address this issue promptly to maintain site security.

CVE Details

  • Product: Joomla! Core
  • Published: August 18, 2026
  • Severity: Medium (CVSS Score 6.5)
  • Status: Analyzed

Affected Products

The vulnerability impacts Joomla! CMS installations running the following versions:

  • Joomla! versions 4.0.0 through 5.4.7
  • Joomla! versions 6.0.0 through 6.1.2

If your website is running any of these versions, it is highly recommended to take action as soon as possible.

Current Status

The vulnerability, CVE-2026-71574, has been thoroughly analyzed. The Joomla! project team has investigated the issue and released fixes to address the inconsistent ACL checks.

Severity Level

This vulnerability carries a Medium severity rating, with a CVSS score of 6.5. A medium severity indicates that while the vulnerability could allow unauthorized actions, it might require specific conditions to be exploited or may not lead to immediate, widespread catastrophic impact. However, the potential for unauthorized data manipulation or other sensitive operations through webservice endpoints makes this a significant concern that demands attention.

Possible Solutions

The good news is that Joomla! has released updates to fix this security flaw. To protect your website from this vulnerability, you should upgrade your Joomla! installation to a patched version immediately.

  • For Joomla! 5.x series, upgrade to version 5.4.8.
  • For Joomla! 6.x series, upgrade to version 6.1.3.

Regularly updating your CMS is one of the most effective ways to secure your website against known vulnerabilities. Always back up your site before performing any updates.

References

https://developer.joomla.org/security-centre/1070-20260803-core-inconsistent-acl-checks-for-mutating-webservice-endpoints.html

https://www.joomla.org/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.