CVE-2026-71570

Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11

Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.


We have discovered 446 live websites that are affected by CVE-2026-71570.

Run a Free Instant Scan




Affected Software

Product  iCagenda
Category Event Management
Vulnerable Domains446 live websites (40% of iCagenda install base)
Vulnerable Versions
  • from 4 through 4.0.12
Vulnerable Versions Count10 versions ( 12% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Aug 14, 2026
  • Updated - Aug 18, 2026

Website Distribution by Country

Number of websites using CVE-2026-71570
United States17 websites



Germany161 websites
France71 websites
Switzerland46 websites
Netherlands45 websites
Italy16 websites
Poland14 websites
Austria12 websites
Belgium8 websites
GB8 websites

Website Distribution by TLD

Number of websites using CVE-2026-71570
.de132 websites
.fr46 websites
.ch43 websites
.nl43 websites
.com43 websites
.org29 websites
.at13 websites
.pl10 websites
.it9 websites
.eu8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-71570

Top websites that are affected by CVE-2026-71570. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org Italy***,***
***.***.cz Czech Republic***,***
********.edu United States***,***
*******************.org France***,***
****************.org France***,***
***.no Norway*,***,***
******.cz Czech Republic*,***,***
********.de Germany*,***,***
*****************.org GB*,***,***
*************.de Germany*,***,***
See full domain list

FAQ

CVE-2026-71570 is Improper Access Control in iCagenda
A total of 446 websites have been identified as vulnerable to CVE-2026-71570, based on global website indexing conducted by WebTechSurvey.
The iCagenda is affected by the CVE-2026-71570 vulnerability.
iCagenda versions up to 4.0.12 are vulnerable to CVE-2026-71570.
CVE-2026-71570 is resolved in version 4.0.12 of iCagenda.