Security
Joomla webservice access flaw fixed in 5.4.4 and 6.0.4
Joomla! CMS versions 4.0.0-5.4.3 and 6.0.0-6.0.3 are affected by an Incorrect Access Control flaw in webservice endpoints. The Joomla project rates its severity as High and probability as Low; administrators should upgrade to 5.4.4 or…
The vulnerability is caused by an improper access check in the core webservice endpoints. According to the Joomla project, the flaw can allow unauthorized access to those endpoints. This makes the issue relevant to administrators whose installations fall within either affected version range, even though the advisory assigns a low probability to exploitation.
The Joomla Security Strike Team recorded the report on 2026-03-09, with the fix released on 2026-03-31. The report was submitted by vnth4nhnt from CyStack. The advisory identifies the affected product as Joomla! CMS and classifies the exploit type as Incorrect Access Control.
Administrators should update through the normal Joomla upgrade process and verify that the installation reaches one of the fixed releases. The advisory does not list a separate workaround, so keeping the CMS on a supported fixed version is the stated remediation.
Published by the Joomla Security Centre.