Joomla Fixes Ten Security Flaws as Umbraco Patches High-Severity CMS Issue

Direct Joomla Updates, Major Upgrades for Unsupported Umbraco Branches
Security graphic featuring Joomla and Umbraco logos beside the headline about security fixes becoming upgrade decisions. The visual frames two same day CMS disclosures as examples of how access control flaws can lead to different remediation paths.

Security updates for Joomla and Umbraco were released on 18 August 2026, including fixes for authentication, authorization and information-exposure weaknesses. Joomla released versions 6.1.3 and 5.4.8 with ten security fixes, according to its release announcement. Umbraco's final security advisory reports four vulnerabilities across its CMS, Forms product and AI Agent, with three classified as Moderate and one as High severity.

Access-control failures recur across both sets of disclosures. Five of Joomla's ten issues involve access-control checks, alongside a multi-factor authentication bypass, while Umbraco disclosed two authorization weaknesses in its CMS backoffice Management API. The remediation paths differ: supported Joomla branches can update to 5.4.8 or 6.1.3, while affected Umbraco CMS installations on end-of-life versions 14, 15 and 16 receive no patch and must move to a supported major version for a complete fix.

The Joomla Security Centre classifies six of the ten vulnerabilities as Moderate severity and four as Low severity. Three carry High impact ratings, including CVE-2026-73337, the multi-factor authentication bypass. Joomla says insufficient state checks can allow two-factor authentication checks to be bypassed and rates the issue Moderate severity, High impact and Moderate probability.

Joomla also rates CVE-2026-71574 Moderate severity but High impact. The flaw allows unauthorized users to perform mutation actions through webservice endpoints where equivalent actions are restricted in the backend interface. The CVE-2026-73373 SHTML upload issue affects Joomla releases back to version 1.0.0, but Joomla rates it Low severity and Low probability because code execution depends on the server executing uploaded SHTML files.

Umbraco's most serious CMS advisory, GHSA-f7m5-5x7g-2p52, is rated High severity with a CVSS 3.1 score of 8.8. An authenticated backoffice user with limited privileges can perform actions reserved for more privileged users and, under the default runtime configuration, potentially execute code in the web application's context. Exploitation requires a valid authenticated backoffice account, with no unauthenticated or self-registration path identified. The flaw affects versions 15.2.0–17.6.1 and 18.0.0–18.1.0 and is fixed in 17.6.2 and 18.1.1.

A separate Moderate vulnerability, GHSA-w5q3-9wf8-43gg, affects Umbraco CMS 14.0.0–17.6.1 and 18.0.0–18.1.0. Search-index Management API endpoints can expose content, media and member data beyond a backoffice user's assigned permissions, including unpublished and access-protected content. Umbraco says equivalent functionality in version 13 was correctly restricted and that the authorization check was lost when the endpoints were reimplemented.

Umbraco CMS versions 14, 15 and 16 have reached end of life and will not receive patches for the affected CMS issues. Umbraco directs installations on those branches to version 17 LTS or version 18. The High-severity flaw begins with version 15.2.0 and does not affect version 14, while the Moderate search-authorization flaw affects the published 14.0.0–17.6.1 range.

Umbraco also released Forms versions 13.9.9, 17.4.8 and 18.0.6 for a Moderate vulnerability affecting forms with fields configured as sensitive. For Umbraco AI Agent, versions 1.6.0–1.10.4, 17.0.0–17.1.3 and 18.0.0–18.1.3 are affected by a separate Moderate vulnerability involving files attached to AI chats. Fixed AI Agent releases are 17.1.4 and 18.1.4; Umbraco does not provide a patched 1.x release and directs those users to a supported major line. Umbraco Cloud applies the CMS and Forms fixes automatically, while the AI Agent update remains manual.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Related Organizations

Upcoming Events

Latest Opportunities