Skip to content

CVE-2026-73337 CVE-2026-73373 CVE-2026-71574 CVE-2026-71573 CVE-2026-72531 CVE-2026-72532 CVE-2026-73336 CVE-2026-73371 CVE-2026-73372

Joomla! Core security release fixes MFA bypass, SHTML uploads and webservice ACL flaws

High 8.9 Vendor: Joomla! Published

Joomla! Core 4.0.0-5.4.6 and 6.0.0-6.1.2 (and the Joomla! Framework Filesystem package) have multiple flaws, including MFA bypass, SHTML upload and webservice ACL issues. Update to Joomla! CMS 5.4.8 or 6.1.3.

What happened

Joomla! has published a security release covering nine flaws in Joomla! Core. The most serious is CVE-2026-73337, an MFA authentication bypass: insufficient state checks allow the second-factor check to be bypassed from the network without user interaction. CVE-2026-73373 allows unrestricted upload of SHTML files; on servers that execute those files, an attacker who can upload files could achieve code execution.

Three webservice ACL issues follow. CVE-2026-71574 permits unauthorised mutation actions through webservice endpoints where the same action is restricted in the backend. CVE-2026-72531 and CVE-2026-72532 allow unauthorised users to create fields or categories via webservices. The release also includes improper CORS origin validation (CVE-2026-71573), XSS through schema.org output (CVE-2026-73336), and ACL flaws in batch copy and schema.org contact injection (CVE-2026-73371 and CVE-2026-73372). No public disclosure or active exploitation is recorded, and none of the CVEs is listed in CISA KEV.

Who is affected

Most issues affect Joomla! CMS 4.0.0 through 5.4.6 and 6.0.0 through 6.1.2. The SHTML upload flaw also affects Joomla! CMS 1.0.0 through 5.4.6 and the Joomla! Framework Filesystem package 1.0.0 through 3.3.0 and 4.0.0 through 4.2.0. The schema.org XSS and contact injection issues affect Joomla! CMS 5.1.0 through 5.4.6 and 6.0.0 through 6.1.2. Joomla! CMS is commonly an internet-facing content-management platform, so exposed instances should be prioritised.

What to do now

  1. Patch first. Upgrade Joomla! CMS to 5.4.8 or 6.1.3; Joomla lists these as the fixed releases.
  2. If you use the Joomla! Framework Filesystem package, Joomla's advisory does not list a separate fixed version for it; treat any use of that package as exposed and watch Joomla's security centre for further guidance.
  3. No workaround has been published, so patching is the primary remediation.
  4. If your deployment exposes Joomla webservice endpoints, restrict network access to them until patching is complete and review permissions on mutation actions.

How to detect it

Start with version inventory: any Joomla! CMS on 4.0.0-5.4.6 or 6.0.0-6.1.2, and any Framework Filesystem package on the affected ranges, needs attention. If you run Joomla webservice endpoints, review access logs for unexpected create, copy or category-change calls, since several flaws allow unauthorised mutation actions. Joomla's advisory does not provide specific indicators of compromise.

Beyond the patch

This bundle is a reminder that CMS hardening continues after patching. Some of these flaws sit on network-exposed Joomla surfaces and allow unauthorised changes, so continuous visibility of where Joomla is exposed matters. Implementation & Assessment Services can test Joomla deployments for authentication, ACL and injection gaps, while Virtual CISO Services (vCISO) can ensure internet-facing Joomla instances and open ports are covered by exposure management.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-73337, CVE-2026-71574, CVE-2026-71573, CVE-2026-72531, CVE-2026-72532, CVE-2026-73371
Joomla! CMS
4.0.0-5.4.6
6.0.0-6.1.2
5.4.8
6.1.3
CVE-2026-73373
Joomla! CMS
1.0.0-5.4.6
6.0.0-6.1.2
5.4.8
6.1.3
CVE-2026-73373
Joomla! Framework Filesystem package
1.0.0-3.3.0
4.0.0-4.2.0
No fixed version listed yet
CVE-2026-73336, CVE-2026-73372
Joomla! CMS
5.1.0-5.4.6
6.0.0-6.1.2
5.4.8
6.1.3

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.