{"id":"CVE-2026-71574","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-71574","summary":"Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform…","details":"Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.","published":"2026-08-18T16:18:16.457","modified":"2026-08-18T16:18:16.457","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://developer.joomla.org/security-centre/20260803-core-inconsistent-acl-checks-for-mutating-webservice-endpoints.html"},{"type":"WEB","url":"https://www.joomla.org/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T16:18:16.457"}}