CVE-2026-23899
Joomla vulnerability analysis and mitigation

Overview

CVE-2026-23899 is an improper access control vulnerability in Joomla! CMS that allows unauthorized access to webservice endpoints. It affects Joomla! versions 3.0.0 through 5.4.3 and 6.0.0 through 6.0.3, with fixed versions being 5.4.4+ and 6.0.4+. The vulnerability was published on April 1, 2026, and is classified as High severity with a CVSS v3.1 score of 8.8 and a CVSS v4.0 score of 8.6 (GitHub Advisory, Joomla Security Centre).

Technical details

The root cause is classified as CWE-284 (Improper Access Control) — the application fails to properly restrict or verify access to webservice endpoints, allowing requests that should be denied to succeed. An attacker with low-level network access can send crafted requests to these endpoints without proper authorization checks being enforced. The CVSS v4.0 scoring notes that high privileges are required per that metric set, while the CVSS v3.1 score reflects low privileges required, suggesting the access control bypass may be exploitable by authenticated users with minimal permissions. A proof-of-concept has been publicly documented covering both CVE-2026-23898 and CVE-2026-23899 (Undercode Testing, GitHub Advisory).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected Joomla! installation. An attacker can gain unauthorized access to webservice endpoints, potentially reading sensitive data, modifying content or configuration, and disrupting service availability. The vulnerability is scoped to the vulnerable system itself with no subsequent system impact noted in the CVSS v4.0 assessment (GitHub Advisory, Joomla Security Centre).

Exploitability

A proof-of-concept exploit has been publicly documented by Undercode Testing, covering this vulnerability alongside the related CVE-2026-23898 (Undercode Testing). Exploitation has been reported by various sources, though no specific threat actor attribution is available. The EPSS score is approximately 0.014% (0th percentile), indicating a currently low predicted exploitation probability. The vulnerability is detectable by Nessus (plugin 304414) and Qualys (detection ID 531302), and there is no current listing in the CISA KEV catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Joomla! installations running versions 3.0.0–5.4.3 or 6.0.0–6.0.3 using tools like Shodan, Censys, or web crawlers targeting Joomla-specific paths (e.g., /api/ endpoints).
  2. Obtain low-privilege credentials: Acquire or register a low-privileged Joomla! account (e.g., a registered user), as the CVSS v3.1 score indicates low privileges are required for exploitation.
  3. Identify webservice endpoints: Enumerate available Joomla! API/webservice endpoints (e.g., /api/index.php/v1/...) that are intended to be restricted to higher-privilege roles.
  4. Craft unauthorized request: Send HTTP requests to restricted webservice endpoints using the low-privilege session token, bypassing the improper access check.
  5. Achieve unauthorized access: Exploit the missing or insufficient access control to read sensitive data, modify records, or disrupt availability via the exposed endpoints (Joomla Security Centre, Undercode Testing).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to Joomla! API/webservice endpoints (e.g., /api/index.php/v1/) from low-privilege user sessions; requests to endpoints that should be restricted to administrator roles.
  • Logs: Joomla! access logs showing low-privilege accounts accessing administrative or restricted webservice routes; HTTP 200 responses to API calls that should return 403 Forbidden for the requesting user's role.
  • File System: Unexpected modifications to Joomla! content, configuration files, or user records that correlate with webservice API activity.
  • Process/Application: Anomalous data exports or content changes initiated via the REST API without corresponding administrator activity in the Joomla! backend audit log.

Mitigation and workarounds

Joomla! has released patched versions addressing this vulnerability: update to 5.4.4 or later for the 5.x branch, or 6.0.4 or later for the 6.x branch (Joomla Security Centre). As an interim workaround, restrict network access to Joomla! webservice/API endpoints using firewall rules or a web application firewall (WAF), and disable webservice endpoints entirely if they are not required for operations. Monitor webservice endpoint access logs for suspicious activity and enforce the principle of least privilege for all user accounts.

Community reactions

Security Online Info covered the Joomla! patch release in the context of both CVE-2026-23898 and CVE-2026-23899, highlighting the file deletion and webservice access risks (Security Online). Undercode Testing published a video walkthrough demonstrating exploitation and hardening techniques for both vulnerabilities (Undercode Testing). The vulnerability was also noted on Bluesky by CVE tracking accounts shortly after disclosure, reflecting routine community awareness activity.

Additional resources


SourceThis report was generated using AI

Related Joomla vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71573MEDIUM6.9
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoYesAug 18, 2026
CVE-2026-73372MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoYesAug 18, 2026
CVE-2026-73336MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoYesAug 18, 2026
CVE-2026-72531MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoYesAug 18, 2026
CVE-2026-71572MEDIUM4.8
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management