CVE-2026-23898Disclosure(joomla / joomla\!)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch joomla joomla\! systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joomla\!

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 4 mentions (2026-04-03); latest day: 2
  • 12 total mentions across 8 days

Affected systems

Vendors
Products
joomla\!

Deep dive

Activity timeline12 mentions / 8d
01234Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-04-03: 4Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Mentions · 2026-05-22: 1Mentions · 2026-05-28: 1Mentions · 2026-06-07: 2PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-03: 3Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 3Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 1Technical Details · 2026-05-22: 104-0104-0204-0304-0804-0905-2205-2806-07
Signal classification4 categories
Disclosure
541.7%
General
325.0%
Patch
325.0%
Exploit
18.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-011
General1
2026-04-021
Patch1
2026-04-034
Disclosure2Patch2
2026-04-081
Disclosure1
2026-04-091
Exploit1
2026-05-221
Disclosure1
2026-05-281
General1
2026-06-072
Disclosure1General1
Full discourse12 posts
  • Hunter@HunterMapping
    Patch

    🚨Alert🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Flaws Exposed in Joomla. 📊 1M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Joomla%22 👇Query HUNTER : http://product.name="Joomla" 📰Refer:https://securityonline.info/joomla-security-patch-cve-2026-23898-file-deletion-risk/ https://developer.joomla.org/security-centre/1031-20260305-core-arbitrary-file-deletion-in-com-joomlaupdate.html https://developer.joomla.org/security-centre/1032-20260306-core-improper-access-check-in-webservice-endpoints.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post alerts that CVE-2026-23898 and CVE-2026-23899 expose critical file deletion and webservice flaws in Joomla, and it provides links to patch or advisory pages for remediation.

    1310114526.7K
    25.9K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-23898: Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate Joomla Autoupdate Server Allows Arbitrary File Deletion Attackers can bypass input validation in Joomla's autoupdate server endpoint by supplying crafted file paths (e.g., via directory traversal or unfiltered filenames), resulting in deletion of arbitrary files on the web server filesystem with web server privileges. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-23898 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-23898" Search Dork: app="Joomla" Exposure: 125.5k+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJKb29tbGEi&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260403 #Joomla #ArbitraryFileDeletion #CVE202623898 #InputValidation #WebServerExploit #DarkEye

    Post summary

    The tweet announces the new Joomla! Core CVE-2026-23898, describing its arbitrary file deletion vulnerability and linking to a full analysis, while also highlighting widespread exposure detected by ZoomEye.

    114033176.0K
    12.2K followersView on X
  • Anastasis Vasileiadis@Anastasis_King
    Disclosure

    🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Flaws Exposed in Joomla. 👇Dorks HUNTER : http://product.name="Joomla" https://t.co/604HNEX7Et

    Post summary

    The tweet announces two Joomla CVEs (2026‑23898 and 2026‑23899) describing them as file‑deletion and webservice flaws, but offers no proof of concept, exploit code, patch, or active exploitation evidence.

    2903273.0K
    10.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Joomla releases critical 8.6 CVSS patches for CVE-2026-23898 & CVE-2026-23899. Prevent arbitrary file deletion and API leaks—update to 5.4.4 or 6.0.4 today! #Joomla #CyberSecurity #InfoSec #Vulnerability #CMS #WebDev #PatchNow #CVE202623898 #WebSecurity https://securityonline.info/joomla-security-patch-cve-2026-23898-file-deletion-risk/ https://t.co/2nZ90pMvom

    Post summary

    Joomla released critical patches for CVE‑2026‑23898 and CVE‑2026‑23899, advising users to update to version 5.4.4 or 6.0.4 to prevent arbitrary file deletion and API leaks.

    04093622
    12.3K followersView on X
  • Cyberkid@Anastasis_King
    Disclosure

    🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Flaws Exposed in Joomla. 👇Dorks HUNTER : http://product.name="Joomla" https://t.co/WhfEo4vDKJ

    Post summary

    The tweet announces the discovery of two critical Joomla vulnerabilities (CVE-2026-23898 and CVE-2026-23899) that allow file deletion and webservice flaws, without mentioning exploitation or remediation.

    02094694
    10.6K followersView on X
  • DarkEye@darkeye_team
    Disclosure

    🚨 Detailed Analysis for CVE-2026-23898 (Alert) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! 🔗 https://www.darkeye.org/vuln/cve/CVE-2026-23898 Critical RCE in widely used open-source logging library — unauthenticated remote code execution via crafted log message. CVE-2026-23898 (note: fictional year; real-world analog is Log4Shell-like) exploits unsafe JNDI lookup in log parsing. Triggered when attacker-controlled input (e.g., HTTP User-Agent) is logged *without sanitization*. Patched in v2.18.0+; legacy deployments remain high-risk. cc: @zoomeye_team (121.5k+ targets detected 🎯) #CVE202623898 #RCE #Log4j #ZeroDay #SupplyChain #ZoomEye

    Post summary

    An analysis of CVE-2026-23898 reveals an unauthenticated remote code execution via JNDI lookup in a logging library, with patch v2.18.0+ available; no PoC or active exploitation is mentioned.

    00032340
    962 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Vendor. 0day Intel: 🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Fl

    Post summary

    The content merely announces the existence of CVE-2026-23898 and CVE-2026-23899 with a vague reference to critical file deletion, but provides no technical details, exploit code, or patch information.

    1000018
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-23898. 0day Intel: 🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Fl

    Post summary

    The tweet is a brief 0day intel disclosure of CVE-2026-23898 (and CVE-2026-23899) noting potential critical file deletion and webservice impact, but offers no PoC, exploit code, patch, or technical details.

    1000035
    253 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-23898 Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. https://www.cve.org/CVERecord?id=CVE-2026-23898

    Post summary

    The post briefly describes CVE-2026-23898 as an arbitrary file deletion flaw caused by missing input validation in an autoupdate server, with only a link to the CVE record.

    0001063
    56.9K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Joomla ❗ CVE-2026-23899 ❗ CVE-2026-23898 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-joomla/ https://t.co/jJrtqJJnnh

    Post summary

    The post merely announces two Joomla CVEs and directs readers to a link for further information, lacking detailed technical, exploit, or patch content.

    00000108
    6.7K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Exploit

    🚨 #CVE-2026-23898 & #CVE-2026-23899: Joomla's Critical File Deletion & Webservice Flaws – Exploit, Detect, and Harden Now + Video https://undercodetesting.com/cve-2026-23898-cve-2026-23899-joomlas-critical-file-deletion-webservice-flaws-exploit-detect-and-harden-now-video/ Educational Purposes!

    Post summary

    The tweet promotes a video demonstration of exploiting CVE‑2026‑23898 and CVE‑2026‑23899 and calls for detection and hardening, but does not provide a public exploit script or evidence of real‑world attacks.

    0000030
    464 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2026-21629 CVE-2026-21630 CVE-2026-21631 CVE-2026-21632 CVE-2026-23898 CVE-2026-23899 Joomla 6.0.4 & 5.4.4 Security & Bugfix Release https://www.joomla.org/announcements/release-news/5944-joomla-6-0-4-5-4-4-security-bugfix-release.html

    Post summary

    The text lists several CVE identifiers associated with a Joomla 6.0.4 & 5.4.4 security and bugfix release, indicating that official patches are being issued to mitigate these vulnerabilities.

    00000377
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlajoomla\!---

Explore more