Summary
CVE-2026-78074 is an improper access control vulnerability (CWE-284) affecting the free editions of the miniOrange OAuth Client extension and 22 other miniOrange Joomla extensions. A missing authentication check allows unauthenticated remote attackers to delete arbitrary installed extensions on an affected Joomla site. The flaw carries a base score of 8.8 (HIGH).
Technical details
- Root cause: the affected extensions lack a proper authentication/authorization check on the extension deinstallation function.
- Trigger condition: an unauthenticated actor sends a request that invokes the deinstallation routine; no credentials or prior session are required.
- Attack vector: network-based, no user interaction, no privileges required, low attack complexity.
- Impact: attackers can remove arbitrary installed Joomla extensions, including security or authentication components, without authenticating — enabling site disruption or weakening of other defenses. Only the free versions of the listed extensions are affected.
Affected software
- miniOrange OAuth Client: 1.0.0–3.2.0
- JoomShield: 1.0.0–1.0.2
- Okta User Sync: 1.0.0–1.1.0
- Keycloak User Sync: 1.0.0–1.1.0
- Restrict Files/Folders/Media Access: 1.0.0–3.7
- LDAP Integration: 1.0.0–6.4.7
- Keycloak OAuth SSO: 1.0.0–1.2.2
- SAML SSO Login with Google Apps: 1.0.0–6.4
- SAML SP Single Sign On – ADFS: 1.0.0–6.4
- Web3 – Crypto Wallet Login: 1.0.0–3.5.1
- Azure AD OAuth SSO: 1.0.0–1.2.2
- Azure User Provisioning: 1.0.0–1.1.0
- JoomAI: 1.0.0–1.0.5
- Educational SSO: 1.0.0–1.2.2
- Two Factor Authentication: 1.0.0–5.0.9
- OTP Verification: 1.0.0–6.6
- SAML 2.0 IDP: 1.0.0–7.7
- Staff/Employee Directory: 1.0.0–2.0.4
- SAML SSO: 1.0.0–11.0.2
- OAuth Server: 1.0.0–5.1.5
- SCIM User Provisioning: 1.0.0–4.0.5
- Custom API: 1.0.0–4.2
- Import Export Users: 1.0.0–4.6
Severity
Base score: 8.8 (HIGH). Published vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N (network-based, low attack complexity, no privileges or user interaction required, high integrity and availability impact).
Mitigation and recommended actions
- Immediate: upgrade each affected extension to a version released after the vulnerable range listed above (e.g., a release newer than 3.2.0 for the miniOrange OAuth Client), obtained directly from miniOrange’s official extension pages.
- If no patch is yet available for a given extension: temporarily disable or uninstall the affected extension via Joomla’s Extensions → Manage console until a fixed release is confirmed, and monitor the site for unexpected extension removals in the interim.
- Restrict or monitor access to the Joomla administrator and extension-management endpoints as an additional layer of defense while patching is completed.

