Security
AcyMailing 11.1.0 fixes two serious Joomla flaws
AcyMailing 11.1.0 fixes two serious security flaws affecting earlier versions with certain features enabled, including an arbitrary file-write issue and a file-deletion flaw.
Vendor Acyba released AcyMailing 11.1.0 for Joomla on 24 September 2026. The update addresses issues in versions below 11.1.0 where the affected features are in use. mySites.guru identified the fixes by comparing the 11.0.5 and 11.1.0 code, rather than reproducing either flaw on a test site.
- A mailbox-actions issue in POP3 mode could allow someone able to email a monitored mailbox to write files, including PHP files, into the web root. mySites.guru gives this a provisional CVSS score of 9.2 Critical.
- A file-type custom-field issue could allow a subscriber to delete files outside the intended upload directory, including
configuration.php. The provisional score is 8.3 High.
No CVE identifiers have been assigned. Administrators should update Joomla sites running AcyMailing below 11.1.0, including Starter installations, and review installed add-ons afterward because an older Easy Profile add-on is known to cause a fatal error after the update.
Originally reported by mySites.guru.