
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-71573 is an improper CORS origin validation vulnerability in Joomla! CMS Core, tracked under security advisory [20260802]. An improper implementation prevents configured CORS origins from being properly validated in CORS requests, potentially allowing unauthenticated attackers from arbitrary origins to make cross-origin requests that should be blocked. Affected versions include Joomla! 4.0.0–5.4.7 and 6.0.0–6.1.2. The vulnerability was published on August 18, 2026, with a patch available as of the same date. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Joomla Security Centre).
The root cause is classified under CWE-93 (Improper Neutralization of CRLF Sequences / CRLF Injection), though the functional impact is an improper CORS origin validation bypass. The vulnerability arises because Joomla's CORS handling logic fails to correctly validate the Origin header against the administrator-configured allowlist, allowing requests from unauthorized origins to be processed as if they were permitted. Exploitation requires no authentication, no user interaction, and no special privileges — only network access to the target Joomla instance. No public proof-of-concept code has been identified at this time (GitHub Advisory, Joomla Security Centre).
Successful exploitation allows an unauthenticated attacker from any origin to issue cross-origin HTTP requests to the Joomla application that should be blocked by the configured CORS policy. The primary impact falls on subsequent systems rather than the vulnerable system itself — with low confidentiality, integrity, and availability impact on dependent systems (e.g., browsers or downstream services relying on CORS enforcement). This could enable unauthorized data access or unauthorized actions exposed via CORS-enabled API endpoints, depending on the application's functionality and session handling (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time. The EPSS score is 0.0, indicating a very low current probability of exploitation. The vulnerability is automatable (no user interaction required) and exploitable over the network without credentials, which lowers the barrier for potential future exploitation. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Joomla Security Centre).
Joomla has released patches addressing this vulnerability. Administrators running the 4.x/5.x branch should upgrade beyond version 5.4.7, and those on the 6.x branch should upgrade beyond version 6.1.2. As a configuration-based mitigation, administrators should review and restrict CORS origin settings to only explicitly trusted domains, and monitor cross-origin request logs for anomalous activity. Upgrading to the latest patched release is the recommended primary remediation (Joomla Security Centre, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."