Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla com_media path traversal requires an update

Joomla! CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 should be upgraded to 5.4.6 or 6.1.1 to address a Moderate path traversal vulnerability.

The Joomla project’s advisory covers an issue in the search parameter handled by the com_media files API webservice endpoint. Improper validation of that parameter can allow path traversal, making this a relevant update for administrators using affected Joomla! CMS installations.

The published details are:

  • Affected versions: 4.0.0-5.4.5,6.0.0-6.1.0
  • Fixed versions: 5.4.6,6.1.1
  • CVE: CVE-2026-40384
  • Exploit type: Path traversal
  • Severity: Moderate
  • Impact: Moderate
  • Probability: Low

The issue was reported on 2026-04-15 and fixed on 2026-05-26. Doyensec reported it in collaboration with Claude and Anthropic Research. Administrators should plan the applicable Joomla! CMS upgrade and verify that their deployment is running one of the fixed versions. The Joomla Security Centre lists the JSST as the contact for further information.

Published by the Joomla Security Centre.