Security
Joomla fixes ACL flaw in web service edit tasks
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix CVE-2026-92226.
The Joomla project has fixed an access control vulnerability affecting web service edit tasks in Joomla! CMS. The issue could allow unauthorized users to perform edit actions on items that should not be editable.
The affected releases are:
Joomla! CMS4.0.0-5.4.8Joomla! CMS6.0.0-6.1.3
Administrators should upgrade to 5.4.9 or 6.1.4, according to the branch they operate. The project classifies the exploit type as Incorrect Access Control. It assigns the issue a severity of Moderate, with High impact and Moderate probability.
The vulnerability was reported by Google and Ada Logics. It is tracked as CVE-2026-92226. Sites should apply the relevant update promptly, particularly where web services are enabled or accessible to users who do not have full administrative privileges.
Published by the Joomla Security Centre.