CVE-2026-49049
Analyzed
Published: 29 Jun 2026, 14:34
Last modified:12 Aug 2026, 13:58
Vulnerability Summary
Overall Risk (default)
medium
36/100 CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
28.31% HIGH
28% probability 0.00%
KEV
Listed
ENISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
29 Jun 2026, 14:34
Published
Vulnerability first disclosed
10 Jul 2026, 00:00
Added to ENISA KEV
Added to Known Exploited Vulnerabilities catalog
12 Aug 2026, 13:58
Last Modified
Vulnerability information updated
Description
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Trends
Current EPSS score: 28.31%• Percentile: 98%
Techniques & Countermeasures
- CWE-284•Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Affected Systems
- joomshaper.com•helix3 extension for joomla
1.0-3.1.1
- ollyo•helix3
≥ 1.0, ≤ 3.1.1