Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to patched versions: miniOrange Oauth Client - 3.2.1, JoomShield by miniOrange - 1.0.3, Okta User sync/Bi-directional user management - 1.1.1, Keycloak user sync / User management - 1.1.1, Restrict Files / Folders / Media Access for Joomla - 3.8, LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login - 6.4.8, Login with Keycloak OAuth Single Sign-On (SSO) | Login with Keycloak - 1.2.3, SAML SSO login with google Apps - 6.5, SAML SP Single Sign On – Login with ADFS -6.5, Web3 – Crypto wallet Login & NFT token gating - 3.5.2, OAuth Single Sign-On - OIDC SSO | Login with Azure AD - 1.2.3, miniOrange User Provisioning with Azure for Joomla -1.1.1, JoomAI - AI Assistant for Joomla -1.0.6, Single Sign On for Educational Institutes - 1.2.3, Two Factor Authentication 2FA for Joomla -5.1.0, OTP Verification For Joomla - 6.7, SAML 2.0 IDP for Joomla - 7.8, Staff/Employee Business Directory Search for Active Directory - 2.0.5, SAML SSO for Joomla - 11.0.3, OAuth Server for Joomla - 5.1.6, SCIM User Provisioning for Joomla - 4.0.6, Custom API for Joomla - 4.3, Import Export Users for Joomla - 4.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.miniorange.com/ |
|
Mon, 31 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions - a missing authentication check allows unauthenticated actors to delete arbitrary installed extensions. Only the free versions of the miniOrange plugins are affected. | |
| Title | Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension deinstallation via various miniOrange extensions | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-01T14:53:30.417Z
Reserved: 2026-08-22T14:23:37.801Z
Link: CVE-2026-78074
Updated: 2026-08-31T14:24:03.319Z
Status : Deferred
Published: 2026-08-31T14:17:23.633
Modified: 2026-08-31T19:33:11.197
Link: CVE-2026-78074
No data.
OpenCVE Enrichment
Updated: 2026-08-31T15:30:04Z