Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla ACL issue affects com_ajax access checks

Joomla! CMS installations running 3.0.0-5.4.3 or 6.0.0-6.0.3 are affected by an access-control issue in com_ajax. Administrators should upgrade to 5.4.4 or 6.0.4.

The Joomla project describes the problem as an incorrect access-control configuration in the administrative area. The ajax component was not covered by the standard check for logged-in users, a behavior that could be unexpected for third-party developers integrating with the component.

The advisory identifies the issue as CVE-2026-21629. Its exploit type is Incorrect Access Control, with the project assigning a severity of Low and a probability of Moderate.

  • Affected versions: 3.0.0-5.4.3 and 6.0.0-6.0.3
  • Fixed versions: 5.4.4 and 6.0.4
  • Reported date: 2026-03-11
  • Fixed date: 2026-03-31

Site owners should apply the update that corresponds to their Joomla branch and review any third-party administrative integrations that rely on com_ajax. Developers should also account for the corrected access-check behavior when testing extensions and custom integrations.

Published by the Joomla Security Centre.