Exploit for Improper Access Control in Ollyo Helix3 CVE-2026-49049

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Published 29 Jun 2026Updated 30 Jun 20265 sources
CVSS 7.5 ✓ VERIFIED REFERENCE

What happened

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Affected versions

Helix3 extension for Joomla: 1.0-3.1.1 Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references