PatchSiren cyber security CVE debrief
CVE-2026-73372 Joomla! Project CVE debrief
The Joomla! Core has an improper access check that injects contact information for unaccessible contact items into schema.org snippets. This issue affects Joomla! Core versions 5.1.0-5.4.7 and 6.0.0-6.1.2. The vulnerability is caused by inadequate access controls, allowing unauthorized data injection. Users should review and apply updates to prevent potential exploitation. The vulnerability has a CVSS score of 5.1 and a severity rating of MEDIUM, indicating a moderate level of risk. Joomla! Core users and administrators, as well as security teams and vulnerability management teams, should review and apply updates to prevent potential exploitation of this vulnerability. Additionally, operators and platform administrators may need to verify and enforce proper access controls for schema.org contact data injection. Security teams should monitor for potential exploitation attempts and review compensating controls for exposed systems while remediation is scheduled and verified. This may involve reviewing and updating access control lists, monitoring for suspicious activity, and implementing additional security measures as needed. By taking these steps, users can help prevent potential exploitation of this vulnerability and protect their systems from unauthorized data injection. It is also recommended that users review compensating controls for exposed systems while remediation is scheduled and verified, and monitor for potential exploitation attempts to quickly detect and respond to potential security incidents. Overall, Joomla! Core users and administrators, as well as security teams and vulnerability management teams, should take immediate action to review and apply updates, verify and enforce proper access controls, and monitor for potential exploitation attempts to prevent potential exploitation of this vulnerability. This may involve coordinating with IT teams, security teams, and other stakeholders to ensure that necessary precautions are taken to prevent exploitation.
- Vendor
- Joomla! Project
- Product
- Joomla! CMS
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-03
Who should care
Joomla! Core users and administrators, as well as security teams and vulnerability management teams, should review and apply updates to prevent potential exploitation of this vulnerability. Additionally, operators and platform administrators may need to verify and enforce proper access controls for schema.org contact data injection. Security teams should monitor for potential exploitation attempts and review compensating controls for exposed systems while remediation is scheduled and verified. This vulnerability may impact organizations using Joomla! Core versions 5.1.0-5.4.7 and 6.0.0-6.1.2, and they should take necessary precautions to prevent exploitation. The vulnerability has a CVSS score of 5.1 and a severity rating of MEDIUM, indicating a moderate level of risk. Users should prioritize reviewing and applying updates to prevent potential exploitation. Furthermore, users should verify and enforce proper access controls for schema.org contact data injection to prevent unauthorized data injection. This may involve reviewing and updating access control lists, monitoring for suspicious activity, and implementing additional security measures as needed. By taking these steps, users can help prevent potential exploitation of this vulnerability and protect their systems from unauthorized data injection. It is also recommended that users review compensating controls for exposed systems while remediation is scheduled and verified, and monitor for potential exploitation attempts to quickly detect and respond to potential security incidents. Overall, Joomla! Core users and administrators, as well as security teams and vulnerability management teams, should take immediate action to review and apply updates, verify and enforce proper access controls, and monitor for potential exploitation attempts to prevent potential exploitation of this vulnerability. This may involve coordinating with IT teams, security teams, and other stakeholders to ensure that necessary precautions are taken to prevent exploitation. By prioritizing the review and application of updates, verification and enforcement of proper access controls, and monitoring for potential exploitation attempts,users
Technical summary
The Joomla! Core has an improper access check that injects contact information for unaccessible contact items into schema.org snippets. This issue affects Joomla! Core versions 5.1.0-5.4.7 and 6.0.0-6.1.2. The vulnerability is caused by inadequate access controls, allowing unauthorized data injection. Users should review and apply updates to prevent potential exploitation.
Defensive priority
Medium-priority defensive review recommended due to Improper ACL checks vulnerability in Joomla! Core.
Recommended defensive actions
- Review and apply Joomla! Core updates to versions 5.1.0-5.4.8 and 6.0.0-6.1.3 or later
- Verify and enforce proper access controls for schema.org contact data injection
- Monitor for potential exploitation attempts
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page supports Improper ACL checks vulnerability in Joomla! Core versions 5.1.0-5.4.7 and 6.0.0-6.1.2. The vulnerability allows for contact information injection into schema.org snippets due to improper access controls. Defenders should verify affected versions, review access controls, and monitor for potential exploitation attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73372 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73372
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73372 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73372
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://developer.joomla.org/security-centre/1076-20260809-core-improper-acl-checks-when-injection-schema-org-contact-data.html
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.joomla.org/
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.