CVE-2026-57830
helix_ultimate: Missing Authorization (CVE-2026-57830)
Affected
- ollyo/helix_ultimate
between 1.0..2.2.6
Description
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
ollyohelix_ultimate
1.0 – 2.2.6Metrics
Show all metrics
Severity
critical
80.82
PoC (publicly reported)
9.1
8.8
Published
2026-07-13 08:16 UTC
CWE-862
Weakness classes (CWE)
CWE-862Class
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-23 16:17 UTC· security@joomla.org
- Description: The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. → Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.