CVE Watchtower ← Back to CVE ListCVE-2026-23898NVDVulnerability SummaryLack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.Severity LevelUNKNOWNPublished DateApr 1, 2026Last ModifiedApr 2, 2026Exploitation StatusNo confirmed exploitation yetEPSS Score (30-Day)0.00%ProbabilityRoot Weakness (CWE)N/AExternal Referenceshttps://developer.joomla.org/security-centre/1031-20260305-core-arbitrary-file-deletion-in-com-joomlaupdate.html