Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla com_config webservice access flaw fixed

Joomla CMS administrators running affected 4.x or 6.x versions should upgrade to the corresponding fixed release for an improper access check in com_config webservice endpoints.

The Joomla project has fixed an issue that could allow unauthorized access to com_config webservice endpoints. The vulnerability affects Joomla! CMS versions 4.0.0-5.4.5 and 6.0.0-6.1.0.

The advisory identifies the exploit type as Incorrect Access Control and assigns it a severity of Moderate. Its listed impact is High, while the probability is Low. The issue is tracked as CVE-2026-35223.

  • Installations on the 4.x range should upgrade to 5.4.6.
  • Installations on the 6.x range should upgrade to 6.1.1.

Joomla records the issue as reported on 2026-04-15 and fixed on 2026-05-26. The report was credited to Rishi Shakya and Qi Deng. Administrators should check their deployed version and apply the appropriate update, particularly where webservice access is enabled.

Published by the Joomla Security Centre.