CyberShieldTips
Best Of
How-To Guides
Password Managers
Privacy Tools
Threat Analysis
VPN Reviews
📚 Resources
☰
Home
›
CVE Database
›
Joomla
›
CVE-2026-35223
CVE-2026-35223
An improper access check allows unauthorized access to com_config webservice endpoints.
critical
9.8
CVSS 3.1
Published:
May 26, 2026
Modified:
May 28, 2026
Vendor:
Joomla
Product:
Joomla\!
Description
An improper access check allows unauthorized access to com_config webservice endpoints.
References
https://developer.joomla.org/security-centre/1040-20260508-core-improper-access-check-in-com-config-webservice-endpoints.html
Related CVEs
CVE-2026-48903
medium · 6.1
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48904
critical · 9.8
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-48905
medium · 6.1
Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48896
high · 7.5
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48897
high · 7.5
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48898
critical · 9.8
An improper access check allows privilege escalation through the com_users batch task.