Security
Joomla ACL issue affects com_ajax access checks
Joomla! CMS installations running 3.0.0-5.4.3 or 6.0.0-6.0.3 are affected by an access-control issue in com_ajax. Administrators should upgrade to 5.4.4 or 6.0.4.
The Joomla project describes the problem as an incorrect access-control configuration in the administrative area. The ajax component was not covered by the standard check for logged-in users, a behavior that could be unexpected for third-party developers integrating with the component.
The advisory identifies the issue as CVE-2026-21629. Its exploit type is Incorrect Access Control, with the project assigning a severity of Low and a probability of Moderate.
- Affected versions:
3.0.0-5.4.3and6.0.0-6.0.3 - Fixed versions:
5.4.4and6.0.4 - Reported date: 2026-03-11
- Fixed date: 2026-03-31
Site owners should apply the update that corresponds to their Joomla branch and review any third-party administrative integrations that rely on com_ajax. Developers should also account for the corrected access-check behavior when testing extensions and custom integrations.
Published by the Joomla Security Centre.