
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23899 is an improper access control vulnerability in Joomla! CMS that allows unauthorized access to webservice endpoints. It affects Joomla! versions 3.0.0 through 5.4.3 and 6.0.0 through 6.0.3, with fixed versions being 5.4.4+ and 6.0.4+. The vulnerability was published on April 1, 2026, and is classified as High severity with a CVSS v3.1 score of 8.8 and a CVSS v4.0 score of 8.6 (GitHub Advisory, Joomla Security Centre).
The root cause is classified as CWE-284 (Improper Access Control) — the application fails to properly restrict or verify access to webservice endpoints, allowing requests that should be denied to succeed. An attacker with low-level network access can send crafted requests to these endpoints without proper authorization checks being enforced. The CVSS v4.0 scoring notes that high privileges are required per that metric set, while the CVSS v3.1 score reflects low privileges required, suggesting the access control bypass may be exploitable by authenticated users with minimal permissions. A proof-of-concept has been publicly documented covering both CVE-2026-23898 and CVE-2026-23899 (Undercode Testing, GitHub Advisory).
Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected Joomla! installation. An attacker can gain unauthorized access to webservice endpoints, potentially reading sensitive data, modifying content or configuration, and disrupting service availability. The vulnerability is scoped to the vulnerable system itself with no subsequent system impact noted in the CVSS v4.0 assessment (GitHub Advisory, Joomla Security Centre).
A proof-of-concept exploit has been publicly documented by Undercode Testing, covering this vulnerability alongside the related CVE-2026-23898 (Undercode Testing). Exploitation has been reported by various sources, though no specific threat actor attribution is available. The EPSS score is approximately 0.014% (0th percentile), indicating a currently low predicted exploitation probability. The vulnerability is detectable by Nessus (plugin 304414) and Qualys (detection ID 531302), and there is no current listing in the CISA KEV catalog (Feedly).
/api/ endpoints)./api/index.php/v1/...) that are intended to be restricted to higher-privilege roles./api/index.php/v1/) from low-privilege user sessions; requests to endpoints that should be restricted to administrator roles.Joomla! has released patched versions addressing this vulnerability: update to 5.4.4 or later for the 5.x branch, or 6.0.4 or later for the 6.x branch (Joomla Security Centre). As an interim workaround, restrict network access to Joomla! webservice/API endpoints using firewall rules or a web application firewall (WAF), and disable webservice endpoints entirely if they are not required for operations. Monitor webservice endpoint access logs for suspicious activity and enforce the principle of least privilege for all user accounts.
Security Online Info covered the Joomla! patch release in the context of both CVE-2026-23898 and CVE-2026-23899, highlighting the file deletion and webservice access risks (Security Online). Undercode Testing published a video walkthrough demonstrating exploitation and hardening techniques for both vulnerabilities (Undercode Testing). The vulnerability was also noted on Bluesky by CVE tracking accounts shortly after disclosure, reflecting routine community awareness activity.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."