PatchSiren cyber security CVE debrief
CVE-2026-77029 yootheme.com CVE debrief
The CVE-2026-77029 vulnerability affects Joomla Extension - yootheme.com, specifically versions of Zoo prior to 4.1.66. The vulnerability is caused by missing CSRF tokens on front-end state changes. This could allow an attacker to perform unauthorized actions on the affected system. Administrators and users of Joomla Extension - yootheme.com, particularly those using versions of Zoo prior to 4.1.66, should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-21T12:16:34.097Z and has not been modified since then. Evidence is limited, and further verification is needed to determine the full scope of affected systems and potential impact.
- Vendor
- yootheme.com
- Product
- Zoo extension for Joomla
- CVSS
- MEDIUM 4.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Administrators and users of Joomla Extension - yootheme.com, particularly those using versions of Zoo prior to 4.1.66, should be aware of this vulnerability and take steps to mitigate it. This includes verifying Joomla Extension - yootheme.com version and configuration, checking for updates to Zoo extension version 4.1.66 or later, and implementing compensating controls for CSRF protection.
Technical summary
The CVE-2026-77029 vulnerability affects Joomla Extension - yootheme.com, specifically versions of Zoo prior to 4.1.66. The vulnerability is caused by missing CSRF tokens on front-end state changes. This could allow an attacker to perform unauthorized actions on the affected system. The vulnerability has a Medium severity with a CVSS score of 4.6.
Defensive priority
Organizations using Joomla Extension - yootheme.com should verify their versions and configurations to ensure they are not vulnerable to Missing CSRF tokens on front-end state changes in Zoo.
Recommended defensive actions
- Verify Joomla Extension - yootheme.com version and configuration
- Check for updates to Zoo extension version 4.1.66 or later
- Implement compensating controls for CSRF protection
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE-2026-77029 record indicates a Medium severity vulnerability with a CVSS score of 4.6. The vulnerability affects Joomla Extension - yootheme.com, specifically versions of Zoo prior to 4.1.66. Evidence is limited, and further verification is needed to determine the full scope of affected systems and potential impact.
Official resources
-
CVE-2026-77029 CVE record
CVE.org
-
CVE-2026-77029 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T12:16:34.097Z and has not been modified since then.