Risques
- Atteinte à l'intégrité des données
- Contournement de la politique de sécurité
- Exécution de code arbitraire à distance
- Injection de code indirecte à distance (XSS)
Systèmes affectés
- Joomla! versions 3.x à 5.x antérieures à 5.4.8
- Joomla! versions 6.x antérieures à 6.1.3
Résumé
De multiples vulnérabilités ont été découvertes dans Joomla!. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données et une injection de code indirecte à distance (XSS).
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
- Bulletin de sécurité Joomla! 1068-20260801 du 18 août 2026 https://developer.joomla.org/security-centre/1068-20260801-core-response-header-injection-in-download-views.html
- Bulletin de sécurité Joomla! 1069-20260802 du 18 août 2026 https://developer.joomla.org/security-centre/1069-20260802-core-improper-cors-origin-validation.html
- Bulletin de sécurité Joomla! 1070-20260803 du 18 août 2026 https://developer.joomla.org/security-centre/1070-20260803-core-inconsistent-acl-checks-for-mutating-webservice-endpoints.html
- Bulletin de sécurité Joomla! 1071-20260804 du 18 août 2026 https://developer.joomla.org/security-centre/1071-20260804-core-improper-acl-checks-for-custom-fields-webservice-endpoints.html
- Bulletin de sécurité Joomla! 1072-20260805 du 18 août 2026 https://developer.joomla.org/security-centre/1072-20260805-core-improper-acl-checks-for-category-webservice-endpoints.html
- Bulletin de sécurité Joomla! 1073-20260806 du 18 août 2026 https://developer.joomla.org/security-centre/1073-20260806-core-xss-through-schema-org-outputs.html
- Bulletin de sécurité Joomla! 1074-20260807 du 18 août 2026 https://developer.joomla.org/security-centre/1074-20260807-core-mfa-authentication-bypass.html
- Bulletin de sécurité Joomla! 1075-20260808 du 18 août 2026 https://developer.joomla.org/security-centre/1075-20260808-core-improper-acl-checks-for-batch-copy-actions.html
- Bulletin de sécurité Joomla! 1076-20260809 du 18 août 2026 https://developer.joomla.org/security-centre/1076-20260809-core-improper-acl-checks-when-injection-schema-org-contact-data.html
- Bulletin de sécurité Joomla! 1077-20260810 du 18 août 2026 https://developer.joomla.org/security-centre/1077-20260810-core-unrestricted-uploads-of-shtml-files.html
- Référence CVE CVE-2026-71572 https://www.cve.org/CVERecord?id=CVE-2026-71572
- Référence CVE CVE-2026-71573 https://www.cve.org/CVERecord?id=CVE-2026-71573
- Référence CVE CVE-2026-71574 https://www.cve.org/CVERecord?id=CVE-2026-71574
- Référence CVE CVE-2026-72531 https://www.cve.org/CVERecord?id=CVE-2026-72531
- Référence CVE CVE-2026-72532 https://www.cve.org/CVERecord?id=CVE-2026-72532
- Référence CVE CVE-2026-73336 https://www.cve.org/CVERecord?id=CVE-2026-73336
- Référence CVE CVE-2026-73337 https://www.cve.org/CVERecord?id=CVE-2026-73337
- Référence CVE CVE-2026-73371 https://www.cve.org/CVERecord?id=CVE-2026-73371
- Référence CVE CVE-2026-73372 https://www.cve.org/CVERecord?id=CVE-2026-73372
- Référence CVE CVE-2026-73373 https://www.cve.org/CVERecord?id=CVE-2026-73373