Home

Description

The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction.

PUBLISHED Reserved 2026-01-01 | Published 2026-02-20 | Updated 2026-02-23 | Assigner Joomla




CRITICAL: 9.5CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-284 Improper Access Control

Product status

Default status
unaffected

4.10.14–6.0.37
affected

Default status
unaffected

3.2.12–5.1.0
affected

Default status
unaffected

6.0.0–7.1.0
affected

Default status
unaffected

5.1.7–6.1.0
affected

Default status
unaffected

2.2.0–3.1.0
affected

Default status
unaffected

1.0.0–2.1.0
affected

Credits

p1r0x / ssd-disclosure.com finder

References

tassos.gr product

cve.org (CVE-2026-21627)

nvd.nist.gov (CVE-2026-21627)

Download JSON