Joomla! Improper ACL Checks Vulnerability (CVE-2026-72532) — Medium Severity

A recently discovered security flaw in Joomla! CMS could allow unauthorized individuals to create categories they shouldn’t have access to. This issue, identified as CVE-2026-72532, stems from improper checks in how Joomla! handles access permissions for its category webservice endpoints. While rated as a Medium severity vulnerability, it’s crucial for website administrators and developers to address this promptly to maintain the integrity and security of their Joomla! installations.

CVE Details

This vulnerability affects Joomla! Core, specifically concerning its category webservice endpoints. The issue was published on August 18, 2026, and is currently classified as “Analyzed” by the National Vulnerability Database.

  • Product: Joomla! CMS
  • Published Date: August 18, 2026
  • Severity: Medium
  • Status: Analyzed

Affected Products

The improper access control vulnerability impacts several versions of Joomla! CMS. Specifically, users running the following versions are vulnerable:

  • Joomla! 4.0.0 through 5.4.7
  • Joomla! 6.0.0 through 6.1.2

Current Status

The vulnerability has been thoroughly analyzed, and patches have been released by the Joomla! Security Strike Team. The issue was reported on July 15, 2026, and fixed on August 18, 2026.

Severity Level

CVE-2026-72532 is rated with a Medium severity. This indicates that while the vulnerability is not immediately critical, it could lead to unauthorized actions, such as creating new categories within components that a user should not be able to modify. Such unauthorized actions can disrupt content management, potentially leading to website defacement or misorganization.

Possible Solutions

To protect your Joomla! website from this improper access control vulnerability, it is strongly recommended to update your CMS installation immediately. The Joomla! project has released specific versions that contain the necessary fixes:

  • For Joomla! 5.4.x users, upgrade to version 5.4.8.
  • For Joomla! 6.1.x users, upgrade to version 6.1.3.

Regularly updating your Joomla! installation is the best defense against known vulnerabilities and ensures your site benefits from the latest security enhancements.

References

https://developer.joomla.org/security-centre/1072-20260805-core-improper-acl-checks-for-category-webservice-endpoints.html

https://www.joomla.org/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.