Security
AcyMailing privilege escalation also affects Joomla sites
A privilege-escalation vulnerability identified as CVE-2026-3614 also affects Joomla installations of AcyMailing, despite public advisories describing the issue as WordPress-only.
Research published by mySites.guru says the vulnerable code is shared between AcyMailing’s Joomla component and WordPress plugin. The affected range is 9.11.0 through 10.8.1; the vendor fixed the issue in 10.8.2, released on 13 March 2026. AcyMailing’s changelog marks the security fix for both platforms.
The flaw is a high-severity privilege escalation with a CVSS score of 8.8. An authenticated, low-privilege user can reach controller functions without the required authorization and potentially authenticate as another CMS user, including an administrator. The advisory does not report active exploitation.
- Check every Joomla site running
AcyMailing. - Upgrade affected installations from
9.11.0through10.8.1to10.8.2. - After updating, review accounts and site files if an affected installation may already have been accessed.
mySites.guru notes that Joomla’s public vulnerability listings did not include this CVE, which may leave administrators unaware that their sites require action.
Originally reported by mySites.guru.