Detects Joomla CMS versions 4.0.0 through 5.4.3 and 6.0.0 through 6.0.3 where the REST API config endpoint (/api/index.php/v1/config/application) has no authorization check in ApplicationController::displayList(). Any API-authenticated user — even a low-privilege Registered user — can read the full configuration.php including database credentials (host, username, password), SMTP credentials, and the application secret key. The fix in 5.4.4/6.0.4 adds a core.admin permission check, restricting access to Super Admins only.
Is your app exploitable through CVE-2026-23899?
Scan your domain free