Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-57829HighCVSS 8.7CVE published 13 July 2026Added to mySites.guru 7 July 2026

Helix Ultimate Framework (helixultimate) below 2.2.7 - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu)

Helix Ultimate versions before 2.2.7 expose several front-end com_ajax tasks (saveMegaMenuSettings, getMenuItems and deleteMedia) with no ACL or CSRF check (CWE-862, Missing Authorization). An unauthenticated attacker can call saveMegaMenuSettings to write arbitrary content into any menu item params (the helixultimatemenulayout badge and custom_html fields in the #__menu table) and enumerate the whole menu tree via getMenuItems. In the wild this stores a self-propagating XSS payload (CWE-79) that, when a logged-in administrator renders the menu, silently creates a rogue Super User and beacons the credentials to an external server. Fixed in 2.2.7, which enforces CSRF token and permission checks across all Helix Ultimate AJAX actions; 2.2.8 is the current release. Confirmed exploited in the wild in July 2026. Action: update to 2.2.8 now, then audit #__menu params for injected script tags and #__users for unexpected Super User accounts. Temporary mitigation: block requests where option=com_ajax and plugin=helixultimate at the firewall or WAF until updated.

Is my site affected?

CVE-2026-57829 is checked by 2 rules. Find the extension and release line your site runs:

ExtensionAffected versionsFixed inWhat to do
Helix Ultimate Frameworkafter 2.1.4-j3sec up to but not including 2.2.72.2.7Update Helix Ultimate Framework to 2.2.7 for this flaw, or to 2.2.10 or later, which no rule we check matches.
Helix Ultimateafter 2.1.4-j3sec up to but not including 2.2.72.2.7Update Helix Ultimate to 2.2.7 for this flaw, or to 2.2.10 or later, which no rule we check matches.

How CVE-2026-57829 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

8.7 High

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:P User interaction
Passive. Someone has to visit a page

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:H Availability
High. The site can be taken down

What it does beyond the site

SC:N Confidentiality
None. Other systems keep their data
SI:N Integrity
None. Other systems keep their integrity
SA:N Availability
None. Other systems stay up

The rule below is rated Critical for the set of 2 CVEs it covers together, not for this record on its own.

Timeline

  1. 7 July 2026mySites.guru check added for Helix Ultimate Framework (after 2.1.4-j3sec up to but not including 2.2.7)
  2. 7 July 2026mySites.guru check added for Helix Ultimate (after 2.1.4-j3sec up to but not including 2.2.7)
  3. 13 July 2026CVE-2026-57829 record published by its CNA

Rule details

Helix Ultimate - Helix Ultimate (shaper_helixultimate) below 2.2.7 - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu)

Helix Ultimate versions before 2.2.7 expose several front-end com_ajax tasks (saveMegaMenuSettings, getMenuItems and deleteMedia) with no ACL or CSRF check (CWE-862, Missing Authorization). An unauthenticated attacker can call saveMegaMenuSettings to write arbitrary content into any menu item params (the helixultimatemenulayout badge and custom_html fields in the #__menu table) and enumerate the whole menu tree via getMenuItems. In the wild this stores a self-propagating XSS payload (CWE-79) that, when a logged-in administrator renders the menu, silently creates a rogue Super User and beacons the credentials to an external server. Fixed in 2.2.7, which enforces CSRF token and permission checks across all Helix Ultimate AJAX actions; 2.2.8 is the current release. Confirmed exploited in the wild in July 2026. Action: update to 2.2.8 now, then audit #__menu params for injected script tags and #__users for unexpected Super User accounts. Temporary mitigation: block requests where option=com_ajax and plugin=helixultimate at the firewall or WAF until updated.

Affected versions: > 2.1.4-j3sec and < 2.2.7

Full advisory: www.joomshaper.com

Other vulnerabilities in Helix Ultimate Framework and Helix Ultimate

Updating for CVE-2026-57829 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extensions.

Helix Ultimate Framework

Latest safe version: 2.2.10

Helix Ultimate

Latest safe version: 2.2.10

References

CVE-2026-57829 questions

Which versions are affected by CVE-2026-57829?
CVE-2026-57829 is covered by 2 rules: Helix Ultimate Framework after 2.1.4-j3sec up to but not including 2.2.7; Helix Ultimate after 2.1.4-j3sec up to but not including 2.2.7.
How do I fix CVE-2026-57829?
It depends on the extension and release line your site runs. For Helix Ultimate Framework after 2.1.4-j3sec up to but not including 2.2.7: update Helix Ultimate Framework to 2.2.7 for this flaw, or to 2.2.10 or later, which no rule we check matches. For Helix Ultimate after 2.1.4-j3sec up to but not including 2.2.7: update Helix Ultimate to 2.2.7 for this flaw, or to 2.2.10 or later, which no rule we check matches.
How severe is CVE-2026-57829?
Joomla CNA scores it 8.7 (High) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and someone has to visit a page.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.