The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers. | |
| Title | Joomla! Core - [20260301] - ACL hardening in com_ajax | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-04-01T12:44:22.404Z
Reserved: 2026-01-01T04:42:27.960Z
Link: CVE-2026-21629
No data.
Status : Received
Published: 2026-04-01T10:16:15.790
Modified: 2026-04-01T10:16:15.790
Link: CVE-2026-21629
No data.
OpenCVE Enrichment
No data.