CVE-2026-49049

Analyzed
Published: 29 Jun 2026, 14:34
Last modified:12 Aug 2026, 13:58

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
28.31% HIGH
28% probability 0.00%
KEV
Listed
ENISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jun 2026, 14:34
Published
Vulnerability first disclosed
10 Jul 2026, 00:00
Added to ENISA KEV
Added to Known Exploited Vulnerabilities catalog
12 Aug 2026, 13:58
Last Modified
Vulnerability information updated

Description

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 28.31% Percentile: 98%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • joomshaper.comhelix3 extension for joomla

    1.0-3.1.1

  • ollyohelix3

    ≥ 1.0, ≤ 3.1.1

References (1)