CVE-2026-49049
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.
- Ollyo helix3
- ≤ 3.1.1
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.0% (61th percentile)
- Weakness
- CWE-284
- NVD status
- Analyzed
- Published
- 2026-06-29
- Attack patterns
- CAPEC-1
CVE-2026-49049 at NVD
10 known exploits for CVE-2026-49049
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-49049
CVE-2026-49049
CVE-2026-49049
CVE-2026-49049
guardx
Exploit for Improper Access Control in Ollyo Helix3
Exploit for Improper Access Control in Ollyo Helix3
Exploit for Improper Access Control in Ollyo Helix3
Exploit for Improper Access Control in Ollyo Helix3
Exploit for Improper Access Control in Ollyo Helix3