Search Results :

×

miniOrange Extensions for Joomla: Security Vulnerability Fix (CVE-2026-78074)

Status: Resolved in the patched versions listed below

1. Summary

• CVE ID = CVE-2026-78074

• Vulnerability Type = Improper Access Control (CWE-284)

• Affected Versions = All versions before fixed releases (Only Free versions affected)

• Fixed Version = See Fixed Versions list below

2. Overview

A high-severity vulnerability was found in 23 miniOrange Joomla extensions that allows an unauthenticated remote attacker to delete arbitrary installed extensions on an affected site without valid credentials. It affects all free versions before the patched releases. Sites running an older version should update immediately.

3. Technical Details

Root cause: The affected extensions lack proper authentication and authorization checks in the deactivation-feedback handler, allowing unauthenticated requests to execute the extension deinstallation routine.

Attack vector: The vulnerability can be exploited remotely over the network. It requires no valid credentials, low attack complexity, and no interaction from the targeted user or administrator; an attacker only needs to send a request invoking the deinstallation routine.

Impact: Exploiting this issue enables attackers to remove arbitrary installed Joomla extensions, including critical security or authentication components, causing site disruption and weakening site defenses.

4. Fixed Versions

Free editions of the following miniOrange Joomla extensions:

Joomla Extension Affected Version Fixed Version
miniOrange OAuth Client Before 3.2.1 3.2.1 and later
JoomShield by miniOrange Before 1.0.3 1.0.3 and later
Okta User Sync/Bi-directional User Management Before 1.1.1 1.1.1 and later
Keycloak User Sync / User Management Before 1.1.1 1.1.1 and later
Restrict Files / Folders / Media Access for Joomla Before 3.8 3.8 and later
LDAP Integration with Active Directory and OpenLDAP – NTLM & Kerberos Login Before 6.4.8 6.4.8 and later
Login with Keycloak OAuth Single Sign-On (SSO) | Login with Keycloak Before 1.2.3 1.2.3 and later
SAML SSO Login with Google Apps Before 6.5 6.5 and later
SAML SP Single Sign-On – Login with ADFS Before 6.5 6.5 and later
Web3 – Crypto Wallet Login & NFT Token Gating Before 3.5.2 3.5.2 and later
OAuth Single Sign-On - OIDC SSO | Login with Azure AD Before 1.2.3 1.2.3 and later
miniOrange User Provisioning with Azure for Joomla Before 1.1.1 1.1.1 and later
JoomAI - AI Assistant for Joomla Before 1.0.6 1.0.6 and later
Single Sign-On for Educational Institutes Before 1.2.3 1.2.3 and later
Two-Factor Authentication 2FA for Joomla Before 5.0.10 5.0.10 and later
OTP Verification for Joomla Before 6.7 6.7 and later
SAML 2.0 IDP for Joomla Before 7.8 7.8 and later
Staff/Employee Business Directory Search for Active Directory Before 2.0.5 2.0.5 and later
SAML SSO for Joomla Before 11.0.3 11.0.3 and later
OAuth Server for Joomla Before 5.1.6 5.1.6 and later
SCIM User Provisioning for Joomla Before 4.0.6 4.0.6 and later
Custom API for Joomla Before 4.3 4.3 and later
Import/Export Users for Joomla Before 4.7 4.7 and later

5. Vulnerability Resolution

In the patched versions, the deactivation-feedback handler no longer performs extension uninstallation for unauthenticated requests. The execution path is now strictly restricted to the administrator application, requires an authenticated user holding the 'core.manage' permission for com_installer, is protected by a Joomla CSRF token, and will only act upon extension IDs belonging to the miniOrange package itself while ignoring attacker-supplied extension IDs.

6. Remediation Steps

1. Log in to the miniOrange portal using this link: https://portal.miniorange.com/ (with the same credentials used to procure the licence).

2. Navigate to the Downloads section from the left vertical menu bar.

3. Download the latest version of the applicable extension(s).

4. Update the installed miniOrange extension(s) for Joomla to the patched version listed above or later.

5. After updating, confirm the extension is running the patched version or later.

Hello there!

Need Help? We are right here!

support