CVE-2026-90904: CWE-284 Improper Access Control in joomshaper.com Easy Store extension for Joomla
Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-level and asset-level ACL permission checks. Any authenticated backend user could edit any EasyStore record, regardless of specific ACL permission grants. Resolved by replacing the hardcoded boolean with proper ACL authorization checks via AccessControl::create()->canEdit()`.
AI Analysis
Technical Summary
The Easy Store extension for Joomla versions 1.0.0 to 3.0.0 contains a broken access control vulnerability (CWE-284) in the ApiController's allowEdit() method. This method was hardcoded to always return true, effectively bypassing Joomla's ACL permission checks at both component and asset levels. Consequently, any authenticated backend user could edit any record in Easy Store without having the appropriate permissions. The vulnerability was fixed by implementing proper ACL checks via AccessControl::create()->canEdit().
Potential Impact
An attacker with authenticated backend access can exploit this vulnerability to edit any Easy Store record regardless of their assigned permissions. This could lead to unauthorized data modification within the Easy Store component, potentially impacting data integrity and business operations relying on this extension.
Mitigation Recommendations
A fix is available that replaces the hardcoded true return in allowEdit() with proper ACL authorization checks using AccessControl::create()->canEdit(). Users should update the Easy Store extension to a version that includes this fix. Since no patch links are provided, check the vendor's official site or Joomla extension repository for the updated version. Until patched, restrict backend user access to trusted administrators only.
CVE-2026-90904: CWE-284 Improper Access Control in joomshaper.com Easy Store extension for Joomla
Description
Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-level and asset-level ACL permission checks. Any authenticated backend user could edit any EasyStore record, regardless of specific ACL permission grants. Resolved by replacing the hardcoded boolean with proper ACL authorization checks via AccessControl::create()->canEdit()`.
CVSS v4.0
Score 8.6high
Affected software
joomshaper.com
Easy Store extension for Joomla
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Easy Store extension for Joomla versions 1.0.0 to 3.0.0 contains a broken access control vulnerability (CWE-284) in the ApiController's allowEdit() method. This method was hardcoded to always return true, effectively bypassing Joomla's ACL permission checks at both component and asset levels. Consequently, any authenticated backend user could edit any record in Easy Store without having the appropriate permissions. The vulnerability was fixed by implementing proper ACL checks via AccessControl::create()->canEdit().
Potential Impact
An attacker with authenticated backend access can exploit this vulnerability to edit any Easy Store record regardless of their assigned permissions. This could lead to unauthorized data modification within the Easy Store component, potentially impacting data integrity and business operations relying on this extension.
Mitigation Recommendations
A fix is available that replaces the hardcoded true return in allowEdit() with proper ACL authorization checks using AccessControl::create()->canEdit(). Users should update the Easy Store extension to a version that includes this fix. Since no patch links are provided, check the vendor's official site or Joomla extension repository for the updated version. Until patched, restrict backend user access to trusted administrators only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-09-14T10:23:04.450Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab42d0cf7a7c541063f0e66
Added to database: 09/23/2026, 19:48:28 UTC
Last enriched: 09/23/2026, 20:02:56 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.