Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN852
_____________________________________________________________________

DATE                : 19/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Joomla! CMS versions prior to
                                      5.4.8, 6.1.3.
 
=====================================================================
https://developer.joomla.org/security-centre/1070-20260803-core-inconsistent-acl-checks-for-mutating-webservice-endpoints.html
https://developer.joomla.org/security-centre/1068-20260801-core-response-header-injection-in-download-views.html
https://developer.joomla.org/security-centre/1071-20260804-core-improper-acl-checks-for-custom-fields-webservice-endpoints.html
https://developer.joomla.org/security-centre/1072-20260805-core-improper-acl-checks-for-category-webservice-endpoints.html
https://developer.joomla.org/security-centre/1073-20260806-core-xss-through-schema-org-outputs.html
https://developer.joomla.org/security-centre/1074-20260807-core-mfa-authentication-bypass.html
https://developer.joomla.org/security-centre/1075-20260808-core-improper-acl-checks-for-batch-copy-actions.html
https://developer.joomla.org/security-centre/1076-20260809-core-improper-acl-checks-when-injection-schema-org-contact-data.html
https://developer.joomla.org/security-centre/1077-20260810-core-unrestricted-uploads-of-shtml-files.html
_____________________________________________________________________


Security Announcements
[20260803] - Core - Inconsistent ACL checks for mutating webservice
endpoints

    Project: Joomla!
    SubProject: CMS
    Impact: High
    Severity: Moderate
    Probability: Low
    Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    Exploit type: Incorrect Access Control
    Reported Date: 2026-07-15
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-71574

Description
An improper access check allows unauthorized users to perform
mutation actions in webservice endpoints, where the same mutation
was restricted in the backend UI.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  Paul, Sorrachat, tms

_____________________________________________________________________


[20260801] - Core - Response header injection in download views

    Project: Joomla!
    SubProject: CMS
    Impact: Low
    Severity: Low
    Probability: Low
    Versions: 3.0.0-5.4.7, 6.0.0-6.1.2
    Exploit type: Response header injection
    Reported Date: 2026-07-02
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-71572

Description
Lack of output processing allowed a header injection in the multiple
download views, leading to reflected file download / content-type
confusion.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  arib06

_____________________________________________________________________

[20260804] - Core - Improper ACL checks for custom fields webservice
endpoints

    Project: Joomla!
    SubProject: CMS
    Impact: Moderate
    Severity: Moderate
    Probability: Low
    Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    Exploit type: Incorrect Access Control
    Reported Date: 2026-07-06
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-72531

Description
An improper access check allows unauthorized users to create fields
for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  ebadfd

_____________________________________________________________________

[20260805] - Core - Improper ACL checks for category webservice
endpoints

    Project: Joomla!
    SubProject: CMS
    Impact: Moderate
    Severity: Moderate
    Probability: Low
    Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    Exploit type: Incorrect Access Control
    Reported Date: 2026-07-15
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-72532

Description
An improper access check allows unauthorized users to create categories
for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

_____________________________________________________________________


[20260806] - Core - XSS through schema.org outputs

    Project: Joomla!
    SubProject: CMS
    Impact: Moderate
    Severity: Moderate
    Probability: Low
    Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
    Exploit type: XSS
    Reported Date: 2026-07-21
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-73336

Description
Improper escaping flags lead to an XSS vector in schema.org markup
outputs.


Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

_____________________________________________________________________

[20260807] - Core - MFA Authentication Bypass

    Project: Joomla!
    SubProject: CMS
    Impact: High
    Severity: Moderate
    Probability: Moderate
    Versions: 4.0.0-5.4.7,6.0.0-6.1.2
    Exploit type: Authentication Bypass
    Reported Date: 2026-07-25
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-73337

Description
Insufficient state checks lead to a vector that allows to bypass
2FA checks.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  bloman, Matej Rada

_____________________________________________________________________

[20260808] - Core - Improper ACL checks for batch copy actions

    Project: Joomla!
    SubProject: CMS
    Impact: Low
    Severity: Low
    Probability: Low
    Versions: 4.0.0-5.4.7,6.0.0-6.1.2
    Exploit type: Incorrect Access Control
    Reported Date: 2026-07-28
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-73371

Description
An improper access check allows unauthorized users to perform copy
batch operations on uneditable items.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  Sabuhi Mammadov

_____________________________________________________________________

[20260809] - Core - Improper ACL checks when injection schema.org
contact data

    Project: Joomla!
    SubProject: CMS
    Impact: Low
    Severity: Low
    Probability: Low
    Versions: 5.1.0-5.4.7,6.0.0-6.1.2
    Exploit type: Incorrect Access Control
    Reported Date: 2026-07-31
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-73372

Description
An improper access check injects contact information for
unaccessible contact items into schema.org snippets.

Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  Stefan Wendhausen

_____________________________________________________________________


[20260810] - Core - Unrestricted uploads of SHTML files

    Project: Joomla!
    SubProject: CMS
    Impact: High
    Severity: Low
    Probability: Low
    Versions: 1.0.0-5.4.7,6.0.0-6.1.2
    Exploit type: Unrestricted Upload of File with Dangerous Type
    Reported Date: 2026-07-29
    Fixed Date: 2026-08-18
    CVE Number: CVE-2026-73373

Description
The default list of dangerous files did not include SHTML files. On
servers that executed these files, that could lead to code
execution.

Affected Installs

Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.
Reported By:  Valentin Lobstein (Chocapikk)

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




