CVE-2026-73337 CVE-2026-73373 CVE-2026-71574 CVE-2026-71573 CVE-2026-72531 CVE-2026-72532 CVE-2026-73336 CVE-2026-73371 CVE-2026-73372
Joomla! Core security release fixes MFA bypass, SHTML uploads and webservice ACL flaws
Joomla! Core 4.0.0-5.4.6 and 6.0.0-6.1.2 (and the Joomla! Framework Filesystem package) have multiple flaws, including MFA bypass, SHTML upload and webservice ACL issues. Update to Joomla! CMS 5.4.8 or 6.1.3.
What happened
Joomla! has published a security release covering nine flaws in Joomla! Core. The most serious is CVE-2026-73337, an MFA authentication bypass: insufficient state checks allow the second-factor check to be bypassed from the network without user interaction. CVE-2026-73373 allows unrestricted upload of SHTML files; on servers that execute those files, an attacker who can upload files could achieve code execution.
Three webservice ACL issues follow. CVE-2026-71574 permits unauthorised mutation actions through webservice endpoints where the same action is restricted in the backend. CVE-2026-72531 and CVE-2026-72532 allow unauthorised users to create fields or categories via webservices. The release also includes improper CORS origin validation (CVE-2026-71573), XSS through schema.org output (CVE-2026-73336), and ACL flaws in batch copy and schema.org contact injection (CVE-2026-73371 and CVE-2026-73372). No public disclosure or active exploitation is recorded, and none of the CVEs is listed in CISA KEV.
Who is affected
Most issues affect Joomla! CMS 4.0.0 through 5.4.6 and 6.0.0 through 6.1.2. The SHTML upload flaw also affects Joomla! CMS 1.0.0 through 5.4.6 and the Joomla! Framework Filesystem package 1.0.0 through 3.3.0 and 4.0.0 through 4.2.0. The schema.org XSS and contact injection issues affect Joomla! CMS 5.1.0 through 5.4.6 and 6.0.0 through 6.1.2. Joomla! CMS is commonly an internet-facing content-management platform, so exposed instances should be prioritised.
What to do now
- Patch first. Upgrade Joomla! CMS to 5.4.8 or 6.1.3; Joomla lists these as the fixed releases.
- If you use the Joomla! Framework Filesystem package, Joomla's advisory does not list a separate fixed version for it; treat any use of that package as exposed and watch Joomla's security centre for further guidance.
- No workaround has been published, so patching is the primary remediation.
- If your deployment exposes Joomla webservice endpoints, restrict network access to them until patching is complete and review permissions on mutation actions.
How to detect it
Start with version inventory: any Joomla! CMS on 4.0.0-5.4.6 or 6.0.0-6.1.2, and any Framework Filesystem package on the affected ranges, needs attention. If you run Joomla webservice endpoints, review access logs for unexpected create, copy or category-change calls, since several flaws allow unauthorised mutation actions. Joomla's advisory does not provide specific indicators of compromise.
Beyond the patch
This bundle is a reminder that CMS hardening continues after patching. Some of these flaws sit on network-exposed Joomla surfaces and allow unauthorised changes, so continuous visibility of where Joomla is exposed matters. Implementation & Assessment Services can test Joomla deployments for authentication, ACL and injection gaps, while Virtual CISO Services (vCISO) can ensure internet-facing Joomla instances and open ports are covered by exposure management.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-73337, CVE-2026-71574, CVE-2026-71573, CVE-2026-72531, CVE-2026-72532, CVE-2026-73371 Joomla! CMS | 4.0.0-5.4.6 6.0.0-6.1.2 | 5.4.8 6.1.3 |
| CVE-2026-73373 Joomla! CMS | 1.0.0-5.4.6 6.0.0-6.1.2 | 5.4.8 6.1.3 |
| CVE-2026-73373 Joomla! Framework Filesystem package | 1.0.0-3.3.0 4.0.0-4.2.0 | No fixed version listed yet |
| CVE-2026-73336, CVE-2026-73372 Joomla! CMS | 5.1.0-5.4.6 6.0.0-6.1.2 | 5.4.8 6.1.3 |
References
Vendor advisory
- Joomla! security announcement [20260807]: MFA Authentication Bypass
- Joomla! security announcement [20260810]: Unrestricted uploads of SHTML files
- Joomla! security announcement [20260803]: Inconsistent ACL checks for mutating webservi…
- developer.joomla.org/security-centre/20260802-core-improper-cors-origin-validation.html
- Joomla! security announcement [20260802]: Improper CORS origin validation
- developer.joomla.org/security-centre/20260804-core-improper-acl-checks-for-custom-field…
- Joomla! security announcement [20260804]: Improper ACL checks for custom fields webserv…
- Joomla! security announcement [20260805]: Improper ACL checks for category webservice e…
Other
CVE
- CVE-2026-73337 — cve.org
- CVE-2026-73337 — NVD
- CVE-2026-73373 — cve.org
- CVE-2026-73373 — NVD
- CVE-2026-71574 — cve.org
- CVE-2026-71574 — NVD
- CVE-2026-71573 — cve.org
- CVE-2026-71573 — NVD
- CVE-2026-72531 — cve.org
- CVE-2026-72531 — NVD
- CVE-2026-72532 — cve.org
- CVE-2026-72532 — NVD
- CVE-2026-73336 — cve.org
- CVE-2026-73336 — NVD
- CVE-2026-73371 — cve.org
- CVE-2026-73371 — NVD
- CVE-2026-73372 — cve.org
- CVE-2026-73372 — NVD