miniOrange LDAP Integration (com_miniorange_dirsync) free edition 1.0.0 to 6.4.7 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)
CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, "LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login (free)", at the CVE's stated affected range 1.0.0-6.4.7. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange LDAP Integration to 6.4.8 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor's own claim: the Joomla Extensions Directory listing for this extension shows 6.4.8 with that release date. This rule's upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component's endpoints at the web application firewall or web server.
Affected versions: ≥ 1.0.0 and ≤ 6.4.7
Full advisory: www.cve.org