A recently discovered security flaw in Joomla! CMS could allow unauthorized individuals to create categories they shouldn’t have access to. This issue, identified as CVE-2026-72532, stems from improper checks in how Joomla! handles access permissions for its category webservice endpoints. While rated as a Medium severity vulnerability, it’s crucial for website administrators and developers to address this promptly to maintain the integrity and security of their Joomla! installations.
CVE Details
This vulnerability affects Joomla! Core, specifically concerning its category webservice endpoints. The issue was published on August 18, 2026, and is currently classified as “Analyzed” by the National Vulnerability Database.
- Product: Joomla! CMS
- Published Date: August 18, 2026
- Severity: Medium
- Status: Analyzed
Affected Products
The improper access control vulnerability impacts several versions of Joomla! CMS. Specifically, users running the following versions are vulnerable:
- Joomla! 4.0.0 through 5.4.7
- Joomla! 6.0.0 through 6.1.2
Current Status
The vulnerability has been thoroughly analyzed, and patches have been released by the Joomla! Security Strike Team. The issue was reported on July 15, 2026, and fixed on August 18, 2026.
Severity Level
CVE-2026-72532 is rated with a Medium severity. This indicates that while the vulnerability is not immediately critical, it could lead to unauthorized actions, such as creating new categories within components that a user should not be able to modify. Such unauthorized actions can disrupt content management, potentially leading to website defacement or misorganization.
Possible Solutions
To protect your Joomla! website from this improper access control vulnerability, it is strongly recommended to update your CMS installation immediately. The Joomla! project has released specific versions that contain the necessary fixes:
- For Joomla! 5.4.x users, upgrade to version 5.4.8.
- For Joomla! 6.1.x users, upgrade to version 6.1.3.
Regularly updating your Joomla! installation is the best defense against known vulnerabilities and ensures your site benefits from the latest security enhancements.
References
https://developer.joomla.org/security-centre/1072-20260805-core-improper-acl-checks-for-category-webservice-endpoints.html
https://www.joomla.org/


