Joomla! CMS Com_ajax Component Access Control Vulnerability

Vulnerability

An access control vulnerability has been identified in the Joomla! CMS ajax component, specifically in versions 3.0.0 prior to 5.4.3 and 6.0.0 prior to 6.0.3. The issue arises because the ajax component was not subjected to the standard logged-in-user verification in the administrative area, potentially leading to unexpected behavior for third-party developers.

Impact

This vulnerability could allow unauthorized access to the ajax component in the administrative area, bypassing the default user authentication checks.

Remediation

Users can upgrade to Joomla! CMS versions 5.4.4 or 6.0.4 to address this vulnerability.

Added: Apr 1, 2026, 10:21 AM
Updated: Apr 1, 2026, 10:21 AM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
5.0
exploitability
7.6
remediation
7.7
relevance
5.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.