CVE-2026-23899

Joomla! Core - [20260306] - Improper access check in webservice endpoints

An improper access check allows unauthorized access to webservice endpoints.


We have discovered 1,518 live websites that are affected by CVE-2026-23899.

Run a Free Instant Scan




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains1,518 live websites (0.71% of Joomla install base)
Vulnerable Versions
  • from 4 through 5.4.3
  • from 6 through 6.0.3
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Apr 1, 2026
  • Updated - Apr 2, 2026

Credits

  • vnth4nhnt from CyStack (finder)

Website Distribution by Country

Number of websites using CVE-2026-23899
United States137 websites



Germany448 websites
France146 websites
Switzerland111 websites
Russia101 websites
Netherlands87 websites
Italy79 websites
GB41 websites
Austria38 websites
Poland34 websites

Website Distribution by TLD

Number of websites using CVE-2026-23899
.de370 websites
.com232 websites
.ch101 websites
.ru91 websites
.org79 websites
.nl76 websites
.fr72 websites
.it55 websites
.net50 websites
.at40 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-23899

Top websites that are affected by CVE-2026-23899. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.**.il Israel**,***
**.******.org United States**,***
*****************.eu Germany***,***
********.org Italy***,***
********************.org United States***,***
**********.com United States***,***
****************.at Austria***,***
***.*******.*******.pl Poland***,***
**********.cz Czech Republic***,***
****.ie Ireland***,***
See full domain list

FAQ

CVE-2026-23899 is Improper Access Control in Joomla
A total of 1,518 websites have been identified as vulnerable to CVE-2026-23899, based on global website indexing conducted by WebTechSurvey.
The Joomla is affected by the CVE-2026-23899 vulnerability.
Joomla versions up to 6.0.3 are vulnerable to CVE-2026-23899.
CVE-2026-23899 is resolved in version 6.0.3 of Joomla.