Exploit for Improper Access Control in Ollyo Helix3 CVE-2026-49049

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

Published 29 Jun 2026Updated 30 Jun 20265 sources
CVSS 7.5 ✓ VERIFIED REFERENCE

Source timeline

Discovered through SploitusView source ↗
CVE record published by NVDView source ↗