Medium severity5.4NVD Advisory· Published Aug 18, 2026· Updated Sep 3, 2026
CVE-2026-72531
CVE-2026-72531
Description
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- developer.joomla.org/security-centre/20260804-core-improper-acl-checks-for-custom-fields-webservice-endpoints.htmlnvdVendor AdvisoryBroken Link
- www.joomla.orgnvdProduct
News mentions
1- Joomla: 17 Vulnerabilities Disclosed, Including Critical Code & SQL Injection FlawsVypr Intelligence · Aug 19, 2026