CVE-2026-23899Disclosure(joomla / joomla\!)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch joomla joomla\! systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper access check allows unauthorized access to webservice endpoints.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joomla\!

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 8 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-04-03); latest day: 2
  • 12 total mentions across 9 days

Affected systems

Vendors
Products
joomla\!

Deep dive

Activity timeline12 mentions / 9d
01122Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-04-03: 2Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Mentions · 2026-04-13: 2Mentions · 2026-05-22: 1Mentions · 2026-05-28: 1Mentions · 2026-06-07: 2Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-03: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-13: 1Technical Details · 2026-05-22: 1Technical Details · 2026-06-07: 104-0104-0204-0304-0804-0904-1305-2205-2806-07
Signal classification3 categories
Disclosure
866.7%
Patch
216.7%
General
216.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-021
Patch1
2026-04-032
Disclosure1Patch1
2026-04-081
Disclosure1
2026-04-091
General1
2026-04-132
Disclosure1General1
2026-05-221
Disclosure1
2026-05-281
Disclosure1
2026-06-072
Disclosure2
Full discourse12 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Flaws Exposed in Joomla. 📊 1M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Joomla%22 👇Query HUNTER : http://product.name="Joomla" 📰Refer:https://securityonline.info/joomla-security-patch-cve-2026-23898-file-deletion-risk/ https://developer.joomla.org/security-centre/1031-20260305-core-arbitrary-file-deletion-in-com-joomlaupdate.html https://developer.joomla.org/security-centre/1032-20260306-core-improper-access-check-in-webservice-endpoints.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces the discovery of two critical Joomla CVEs (CVE‑2026‑23898 and CVE‑2026‑23899) that enable arbitrary file deletion and improper webservice access, and references vendor patch information.

    1310114526.7K
    25.9K followersView on X
  • Anastasis Vasileiadis@Anastasis_King
    Disclosure

    🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Flaws Exposed in Joomla. 👇Dorks HUNTER : http://product.name="Joomla" https://t.co/604HNEX7Et

    Post summary

    The tweet announces two critical Joomla vulnerabilities (CVE‑2026‑23898 & CVE‑2026‑23899) that allow file deletion and exploit webservice flaws, but provides no exploit details, patches, or evidence of active use.

    2903273.0K
    10.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Joomla releases critical 8.6 CVSS patches for CVE-2026-23898 & CVE-2026-23899. Prevent arbitrary file deletion and API leaks—update to 5.4.4 or 6.0.4 today! #Joomla #CyberSecurity #InfoSec #Vulnerability #CMS #WebDev #PatchNow #CVE202623898 #WebSecurity https://securityonline.info/joomla-security-patch-cve-2026-23898-file-deletion-risk/ https://t.co/2nZ90pMvom

    Post summary

    Joomla has released critical patches for CVE‑2026‑23898/23899 that mitigate arbitrary file deletion and API leaks, advising users to update to version 5.4.4 or 6.0.4.

    04093622
    12.3K followersView on X
  • Cyberkid@Anastasis_King
    Disclosure

    🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Flaws Exposed in Joomla. 👇Dorks HUNTER : http://product.name="Joomla" https://t.co/WhfEo4vDKJ

    Post summary

    The tweet announces the newly disclosed vulnerabilities CVE-2026-23898 and CVE-2026-23899 affecting Joomla, describing them as critical file deletion and webservice flaws without mentioning PoCs, exploits, patches, or active use.

    02094694
    10.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Vendor. 0day Intel: 🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Fl

    Post summary

    The post merely alerts to the existence of two new CVEs, offering minimal description of their impact without any technical or mitigation details.

    1000018
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-23898. 0day Intel: 🚨 CVE-2026-23898 & CVE-2026-23899: Critical File Deletion and Webservice Fl

    Post summary

    The post alerts that CVE-2026-23898 (and CVE-2026-23899) are 0day vulnerabilities causing critical file deletion and webservice flaws.

    1000035
    253 followersView on X
  • CyStack@CyStackSecurity
    Disclosure

    🔓 SECURITY BULLETIN: @CyStackSecurity researcher found CVE-2026-21630 (SQL Injection) and CVE-2026-23899 (Improper Access Control) in Joomla REST API, with medium-to-high severity. Full report: https://cystack.net/research/security-joomla-rest-api #CyStack #Cybersecurity #InfoSec #Joomla #CVE #Vulnerability

    Post summary

    A security bulletin from @CyStackSecurity discloses two Joomla REST API vulnerabilities—a SQL injection and an improper access control flaw—both rated medium-to-high severity, along with a link to a full report.

    00010418
  • CyStack@CyStackSecurity
    General

    🔓 SECURITY BULLETIN: @CyStackSecurity researchers recently deep-dived into the Joomla REST API. CVE-2026-21630 and CVE-2026-23899 could allow unauthorized attackers to access sensitive data without credentials. Full report: https://cystack.net/research/security-joomla-rest-api

    Post summary

    The bulletin alerts about two Joomla REST API CVEs that could allow credential‑less data access, but it gives no PoC, exploit, patch, or detailed technical information.

    0001011
    3.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23899 An improper access check allows unauthorized access to webservice endpoints. https://www.cve.org/CVERecord?id=CVE-2026-23899

    Post summary

    The text announces CVE-2026-23899, describing an improper access check that permits unauthorized access to webservice endpoints, without providing PoC, exploit, or patch information.

    0001051
    56.9K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Joomla ❗ CVE-2026-23899 ❗ CVE-2026-23898 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-joomla/ https://t.co/jJrtqJJnnh

    Post summary

    The post announces two new Joomla CVEs and provides a link to a CERT page for further details, but offers no technical or exploit information.

    00000108
    6.7K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 #CVE-2026-23898 & #CVE-2026-23899: Joomla's Critical File Deletion & Webservice Flaws – Exploit, Detect, and Harden Now + Video https://undercodetesting.com/cve-2026-23898-cve-2026-23899-joomlas-critical-file-deletion-webservice-flaws-exploit-detect-and-harden-now-video/ Educational Purposes!

    Post summary

    The post references two Joomla CVEs with generic statements about exploitation and hardening, but it lacks concrete technical details, exploit code, or patch information.

    0000030
    464 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2026-21629 CVE-2026-21630 CVE-2026-21631 CVE-2026-21632 CVE-2026-23898 CVE-2026-23899 Joomla 6.0.4 & 5.4.4 Security & Bugfix Release https://www.joomla.org/announcements/release-news/5944-joomla-6-0-4-5-4-4-security-bugfix-release.html

    Post summary

    Joomla has released security patches for CVE-2026-21629 through CVE-2026-23899 in versions 6.0.4 and 5.4.4, providing a remediation while no exploitation or POC details are disclosed.

    00000377
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlajoomla\!---

Explore more