CVE-2026-57830

helix_ultimate: Missing Authorization (CVE-2026-57830)

criticalPoCEPSS 0.5%

Affected

  • ollyo/helix_ultimate between 1.0..2.2.6

Description

Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

ollyohelix_ultimate
1.0 – 2.2.6

Metrics

9.1
Source: nvd-v3
40.7 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
PoC (publicly reported)
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-13 08:16 UTC
CWE-862

Weakness classes (CWE)

  • CWE-862Class

    Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-23 16:17 UTC· security@joomla.org
    • Description: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. → Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Linked advisories