Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

AcyMailing SQL injection fixed in version 10.11.1

AcyMailing versions 6.0.0 through 10.11.0 contain an unauthenticated SQL injection affecting Joomla and WordPress installations. Administrators should update to version 10.11.1.

mySites.guru published research into the issue, which is tracked as CVE-2026-56292 and was assigned by the Joomla CNA. The advisory rates it CVSS 4.0 8.7 (High). It says the flaw was reported privately to the AcyMailing team before public disclosure.

The vulnerable code was in a public-facing endpoint that accepted unsanitised input in a database query. An attacker without an account could potentially retrieve information from Joomla or WordPress database tables, including user records, password hashes, content and extension configuration data.

  • Affected: AcyMailing 6.0.0 through 10.11.0
  • Fixed: AcyMailing 10.11.1, released 9 July 2026
  • Class: unauthenticated SQL injection
  • Exploitation: the advisory does not report confirmed exploitation

Administrators should back up affected sites and update AcyMailing to 10.11.1 or later through the Joomla Extensions manager or WordPress plugin updater. A web application firewall may reduce exposure, but does not replace patching.

Originally reported by mySites.guru.