CVE-2026-21629: Joomla! Core - [20260301] - ACL hardening in com_ajax
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21629?
CVE-2026-21629 has a medium severity rating due to its potential exploitation by unauthorized users.
How do I fix CVE-2026-21629?
To fix CVE-2026-21629, update your Joomla! installation to the latest version that includes the necessary ACL hardening in the com_ajax component.
What is affected by CVE-2026-21629?
CVE-2026-21629 affects Joomla Core, specifically the ajax component used in the administrative area.
What are the potential risks of CVE-2026-21629?
The potential risks of CVE-2026-21629 include unauthorized access to sensitive functions in the administrative area by third-party developers.
Is there a workaround for CVE-2026-21629?
There are no specific workarounds for CVE-2026-21629 recommended, so please ensure your Joomla! installation is updated.