
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23898 is an arbitrary file deletion vulnerability in Joomla! CMS affecting the com_joomlaupdate (autoupdate server) component. It stems from a lack of input validation in the autoupdate server mechanism, allowing authenticated high-privilege attackers to delete arbitrary files on the server. Affected versions include Joomla! 3.0.0–5.4.3 and 6.0.0–6.0.3; fixed versions are 5.4.4 and 6.0.4. The vulnerability was published on April 1, 2026, with a CVSS v3.1 score of 7.2 (High) and a CVSS v4.0 score of 8.6 (High) (GitHub Advisory, Joomla Advisory).
The root cause is classified as CWE-73 (External Control of File Name or Path), where user-supplied input is not properly validated before being used in filesystem operations within the autoupdate mechanism (com_joomlaupdate). An attacker with administrative credentials can supply a crafted file path parameter to the autoupdate server component, causing the application to delete arbitrary files outside the intended directory. Exploitation requires network access and high-privilege (administrator-level) credentials, but no user interaction is needed. No public proof-of-concept code has been identified at this time (GitHub Advisory, Joomla Advisory).
Successful exploitation allows an authenticated attacker with administrator-level access to delete arbitrary files on the server, resulting in high impacts to confidentiality, integrity, and availability of the affected Joomla! installation. Attackers could delete critical system or application files, causing service disruption, data loss, or destabilizing the CMS in ways that could facilitate further compromise (e.g., deleting configuration or security files to enable subsequent attacks). The vulnerability is scoped to the vulnerable system itself, with no direct impact on subsequent systems (GitHub Advisory, Joomla Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of publication (Feedly). The EPSS score is approximately 0.063% (0th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high-privilege (administrator) credentials, which significantly limits the attacker pool (GitHub Advisory).
/administrator/).com_joomlaupdate component, which handles the autoupdate server mechanism.../../) as input to the autoupdate mechanism's file handling parameter..htaccess, or other critical application/system files.com_joomlaupdate with unusual or path-traversal-containing file path parameters (e.g., ../../); unexpected file deletion events recorded in server-side logs around the time of administrator activity.configuration.php, .htaccess, core CMS files); timestamps of file deletions correlating with administrator login sessions./administrator/index.php?option=com_joomlaupdate with anomalous or encoded path parameters from unexpected IP addresses.apache, nginx, php-fpm) outside of normal update windows.Joomla! has released patched versions 5.4.4 (for the 5.x branch) and 6.0.4 (for the 6.x branch); administrators should upgrade immediately (Joomla Advisory). As interim mitigations, restrict access to the Joomla! administrator backend by IP allowlisting, enforce strong and unique administrator credentials, and monitor administrative account activity closely. Limiting network access to the autoupdate mechanism and maintaining regular, tested backups will reduce the impact of potential exploitation. Apply updates as soon as they are available and monitor the Joomla! Security Centre for further guidance.
Security news outlet SecurityOnline.info covered the vulnerability shortly after disclosure, highlighting the file deletion risk in Joomla! (SecurityOnline). The vulnerability was also discussed alongside a related flaw (CVE-2026-23899) in a technical video by UnderCode Testing, which covered exploitation, detection, and hardening guidance (UnderCode Testing). Community reaction has been moderate, with the vulnerability noted in threat intelligence feeds and vulnerability databases but no significant controversy or widespread alarm, consistent with the requirement for high-privilege credentials to exploit.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."