logo

Joomla! Issues Security Patch: Critical File Deletion and Webservice Flaws Exposed

ID: cf0cc5a7-3300-5174-a3f9-de076a62fba3

STIX ID: report--cf0cc5a7-3300-5174-a3f9-de076a62fba3

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Joomla! released critical security updates for CVE-2026-23898 and CVE-2026-23899 (CVSSv4 8.6): the first allows arbitrary file deletion via a lack of input validation in the com_joomlaupdate autoupdate mechanism and the second allows unauthorized access to webservice endpoints. Affected versions include 4.0.0–5.4.3 and 6.0.0–6.0.3; administrators should upgrade to 5.4.4 or 6.0.4 immediately to mitigate these issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.