CVE-2026-71572
Joomla vulnerability analysis and mitigation

Overview

CVE-2026-71572 is a response header injection vulnerability in Joomla! CMS download views, classified under security advisory [20260801]. The flaw affects Joomla! versions 3.0.0–5.4.7 and 6.0.0–6.1.2, where a lack of output processing allows CRLF-based header injection in multiple download views, leading to reflected file download and content-type confusion attacks. It was published on August 18, 2026, with a patch made available the same day. The vulnerability carries a CVSS v4.0 base score of 4.8 (Medium) (GitHub Advisory, Joomla Security Centre).

Technical details

The root cause is improper neutralization of CRLF sequences (CWE-93) in Joomla's download view output handling. Because user-supplied input is not sanitized before being included in HTTP response headers, an attacker can inject arbitrary CRLF sequences to manipulate response headers — a technique known as HTTP response header injection. Exploitation requires High privileges (PR:H) and passive user interaction (UI:P), meaning the attacker must have some elevated access and a victim must interact with a crafted URL. The attack vector is network-based with low complexity and no special attack requirements (GitHub Advisory, Joomla Security Centre).

Impact

Successful exploitation allows an attacker to inject malicious HTTP response headers, enabling reflected file download attacks and content-type confusion. This can be leveraged for phishing and social engineering by tricking users into downloading malicious files disguised as legitimate Joomla content. There is no direct confidentiality or availability impact on the vulnerable system itself; the primary risk is low-integrity impact on subsequent systems through spoofed responses (GitHub Advisory, Joomla Security Centre).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The requirement for High privileges further limits the practical attack surface (GitHub Advisory, Joomla Security Centre).

Exploitation steps

  1. Identify a target: Locate a Joomla! instance running versions 3.0.0–5.4.7 or 6.0.0–6.1.2 with accessible download views, using tools like Shodan or manual browsing.
  2. Obtain elevated access: Acquire High-privilege credentials (e.g., administrator or editor account) on the target Joomla! site, as the vulnerability requires PR:H.
  3. Craft a malicious URL: Construct a request to a Joomla download view endpoint that includes CRLF sequences (%0d%0a) in a parameter that is reflected into HTTP response headers (e.g., a filename or content-type parameter).
  4. Inject headers: The injected CRLF sequences cause the server to emit attacker-controlled HTTP headers, such as a manipulated Content-Disposition or Content-Type header.
  5. Deliver to victim: Share the crafted URL with a target user. When the victim accesses the URL, their browser receives the manipulated response, potentially triggering an unwanted file download or content-type confusion, enabling phishing or social engineering (GitHub Advisory, Joomla Security Centre).

Indicators of compromise

  • Network: HTTP requests to Joomla download view endpoints containing URL-encoded CRLF sequences (%0d%0a, %0D%0A) in query parameters; unusual Content-Disposition or Content-Type headers in server responses.
  • Logs: Web server access logs showing requests to download endpoints with encoded newline characters in parameter values; repeated access to download views from a single privileged account with anomalous parameter strings.
  • File System: No direct file system artifacts expected, as this is a header injection attack; however, unexpected files delivered to end users via manipulated download responses may indicate exploitation.

Mitigation and workarounds

Joomla! has released patches addressing this vulnerability; users should upgrade to versions beyond 5.4.7 (for the 3.x–5.x branch) and beyond 6.1.2 (for the 6.x branch). As interim mitigations, implement strict input validation and output encoding for all download view parameters to prevent CRLF injection. Deploying a Web Application Firewall (WAF) configured to filter CRLF sequences in HTTP request parameters targeting download endpoints can also reduce risk (Joomla Security Centre, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Joomla vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71573MEDIUM6.9
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-73372MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-73336MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-72531MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-71572MEDIUM4.8
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management