Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.
We have discovered 1,821 live websites that are affected by CVE-2026-71574.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 1,821 live websites (1.36% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 27 versions ( 21% of all versions) |
| 180 websites | |
| 511 websites | |
| 188 websites | |
| 122 websites | |
| 111 websites | |
| 106 websites | |
| 89 websites | |
| 58 websites | |
| 53 websites | |
| 28 websites |
| .de | 440 websites |
| .com | 268 websites |
| .ch | 111 websites |
| .fr | 105 websites |
| .nl | 100 websites |
| .ru | 91 websites |
| .org | 87 websites |
| .it | 59 websites |
| .at | 57 websites |
| .net | 57 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.fr | **,*** | ||
| ************.ru | **,*** | ||
| ******.**.il | **,*** | ||
| **.******.org | **,*** | ||
| **************.com | ***,*** | ||
| *****************.eu | ***,*** | ||
| ********.org | ***,*** | ||
| ********.de | ***,*** | ||
| ****************.at | ***,*** | ||
| *********.de | ***,*** |
FAQ