Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-78074HighPublished 31 August 2026

miniOrange SAML SSO (com_miniorange_saml) free edition 1.0.0 to 11.0.2 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "SAML SSO for Joomla (free)", at the CVE's stated affected range 1.0.0-11.0.2. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange SAML SSO for Joomla to 11.0.3 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 11.0.3 with that release date. Connected sites have already been observed reporting 11.0.3. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 11.0.2

Official record: cve.org · NVD

Every connected Joomla site is checked against these rules on each audit, and flagged if it runs an affected version.

Affected extensions and versions

HighCVE-2026-780742026-08-31

miniOrange OAuth Client - miniOrange OAuth Client (com_miniorange_oauth) free edition 1.0.0 to 3.2.0 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "miniOrange Oauth Client (free)", at the CVE's stated affected range 1.0.0-3.2.0. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update the miniOrange OAuth Client to 3.2.1 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 3.2.1 with that release date. Note that 3.2.1 supersedes the 3.2.0 that fixed the separate CVE-2026-77995 account takeover, so a site sitting on 3.2.0 is patched for that flaw but still exposed to this one. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 3.2.0

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange OAuth Client - miniOrange Login with Azure AD / OAuth OIDC SSO (com_miniorange_oauth) free edition 1.0.0 to 1.2.2 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "OAuth Single Sign-On - OIDC SSO | Login with Azure AD (free)", at the CVE's stated affected range 1.0.0-1.2.2. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update OAuth Single Sign-On - OIDC SSO / Login with Azure AD to 1.2.3 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 1.2.3 with that release date. This product ships under the same com_miniorange_oauth element as the OAuth Client but on its own 1.x numbering, so it is matched on the display name rather than the element alone. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 1.2.2

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange OAuth Client - miniOrange OAuth Server (com_miniorange_oauth) free edition 1.0.0 to 5.1.5 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "OAuth Server for Joomla (free)", at the CVE's stated affected range 1.0.0-5.1.5. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange OAuth Server to 5.1.6 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 5.1.6 with that release date. This product ships under the same com_miniorange_oauth element as the OAuth Client, so it is matched on the display name rather than the element alone. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 5.1.5

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange LDAP Integration - miniOrange LDAP Integration (com_miniorange_dirsync) free edition 1.0.0 to 6.4.7 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login (free)", at the CVE's stated affected range 1.0.0-6.4.7. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange LDAP Integration to 6.4.8 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 6.4.8 with that release date. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 6.4.7

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange Custom API - miniOrange Custom API (com_miniorange_customapi) free edition 1.0.0 to 4.2 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "Custom API for Joomla (free)", at the CVE's stated affected range 1.0.0-4.2. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange Custom API to 4.3 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 4.3 with that release date. Connected sites have already been observed reporting 4.3. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 4.2

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange Import Export Users - miniOrange Import Export Users (com_miniorange_importexportusers) free edition 1.0.0 to 4.6 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "Import Export Users for Joomla (free)", at the CVE's stated affected range 1.0.0-4.6. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange Import Export Users to 4.7 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 4.7 with that release date. The CVE record originally truncated this mid-number in its solution text ("Import Export Users for Joomla - 4."). We reported that to the Joomla CNA on 4 September 2026 and the record was corrected to 4.7 the same morning, which matches what miniOrange gave in writing and what the directory shows. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 4.6

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange Keycloak User Sync - miniOrange Keycloak User Sync (com_miniorange_keycloaksync) free edition 1.0.0 to 1.1.0 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "Keycloak user sync / User management (free)", at the CVE's stated affected range 1.0.0-1.1.0. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange Keycloak User Sync to 1.1.1 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 1.1.1 with that release date. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 1.1.0

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange Restrict Files / Folders - miniOrange Restrict Files / Folders / Media Access (com_miniorange_mediarestriction) free edition 1.0.0 to 3.7 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "Restrict Files / Folders / Media Access for Joomla (free)", at the CVE's stated affected range 1.0.0-3.7. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange Restrict Files / Folders / Media Access to 3.8 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 3.8 with that release date. miniOrange also market this extension as the Joomla Content Access Manager, which is the display name connected sites report for it. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 3.7

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange SCIM User Provisioning - miniOrange SCIM User Provisioning (com_miniorange_scim) free edition 1.0.0 to 4.0.5 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "SCIM User Provisioning for Joomla (free)", at the CVE's stated affected range 1.0.0-4.0.5. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange SCIM User Provisioning to 4.0.6 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 4.0.6 with that release date. miniOrange ship more than one SCIM extension for Joomla and the standalone scim-user-provisioning plugin is versioned on a separate line, so this rule is deliberately confined to the com_miniorange_scim component. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 4.0.5

Full advisory: www.cve.org

HighCVE-2026-780742026-08-31

miniOrange Two Factor Authentication - miniOrange Two Factor Authentication (com_miniorange_twofa) free edition 1.0.0 to 5.0.9 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)

CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "Two Factor Authentication 2FA for Joomla (free)", at the CVE's stated affected range 1.0.0-5.0.9. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange Two Factor Authentication to 5.0.10 or later. miniOrange released the fix on 1 September 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 5.0.10 with that release date. The CVE record originally contradicted itself on this one, giving 5.1.0 in its HTML solution block against 5.0.10 in the plain-text one. We reported it to the Joomla CNA on 4 September 2026 and the record was corrected to 5.0.10 the same morning, which is what miniOrange gave in writing and what the directory shows. This release came a day later than the rest of the set. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.

Affected versions: ≥ 1.0.0 and ≤ 5.0.9

Full advisory: www.cve.org

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 13 September 2026.