Security
Joomla fixes high-severity file deletion flaw in com_joomlaupdate
Joomla administrators running versions 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to fix a high-severity vulnerability in com_joomlaupdate.
The Joomla project has addressed an arbitrary file deletion vulnerability affecting the CMS autoupdate server mechanism. The flaw is caused by inadequate validation of input handled during the update process and could allow files to be removed from a Joomla installation.
The project rates the issue as High severity, with a Low probability of exploitation. It is tracked as CVE-2026-23898.
- Affected: Joomla! CMS
4.0.0-5.4.3 - Affected: Joomla! CMS
6.0.0-6.0.3 - Fixed: Joomla! CMS
5.4.4or6.0.4 - Exploit type: Arbitrary File Deletion
Site owners should check which major Joomla branch their installation uses and apply the corresponding fixed release. Updating also ensures that the vulnerable update functionality is replaced, rather than relying on configuration changes or workarounds. Administrators should use the normal Joomla update process and review their files and access logs if they suspect unexpected deletion activity.
The vulnerability was reported by Phil Taylor. The Joomla Security Centre directs security-related enquiries to the JSST.
Published by the Joomla Security Centre.