Joomla! Issues Security Patch: Critical File Deletion and Webservice Flaws Exposed
ID: cf0cc5a7-3300-5174-a3f9-de076a62fba3
STIX ID: report--cf0cc5a7-3300-5174-a3f9-de076a62fba3
Feed Name: securityonline.info
Threat Score
Joomla! released critical security updates for CVE-2026-23898 and CVE-2026-23899 (CVSSv4 8.6): the first allows arbitrary file deletion via a lack of input validation in the com_joomlaupdate autoupdate mechanism and the second allows unauthorized access to webservice endpoints. Affected versions include 4.0.0–5.4.3 and 6.0.0–6.0.3; administrators should upgrade to 5.4.4 or 6.0.4 immediately to mitigate these issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
