AcyMailing 11.1.0 adds security-related fixes for mailbox uploads and file fields, making a prompt update advisable for Joomla sites using the extension. The release also follows a confirmed Joomla SQL injection fixed in 10.11.1, so administrators should verify that their installation is now at least version 11.1.0.

AcyMailing 11.1.0 contains security-related changes that Joomla administrators should treat as a routine priority update. The available release information identifies fixes concerning mailbox uploads and file fields, but it does not yet provide CVE identifiers, CVSS scores, or a detailed technical advisory for those specific 11.1.0 changes.

What AcyMailing 11.1.0 changes

The AcyMailing 11.1.0 changelog includes two security-related bug-fix entries concerning mailbox uploads and file fields. These are useful reasons to update, especially on sites where AcyMailing manages subscriber data, campaign content, mailboxes, attachments, or forms.

Administrators should keep the scope of the available information clear. The 11.1.0 entries are changelog-level descriptions, not published vulnerability advisories. At the time of review, authoritative records do not assign CVE identifiers or severity scores to the mailbox-upload and file-field fixes. It would therefore be inaccurate to label either change as a particular CVE, to infer a vulnerability class, or to claim that the update eliminates every security risk in AcyMailing.

That uncertainty does not make the update optional. Security maintenance commonly includes defensive changes before detailed public documentation is available. For Joomla sites running an older AcyMailing release, moving to 11.1.0 or later both includes these newer hardening changes and ensures the site has passed the earlier 10.11.1 fix for a confirmed Joomla-specific SQL injection issue.

A third-party release roundup records the 11.1.0 security-related entries, while the AcyMailing website remains the appropriate place to check the current extension release and vendor guidance. Agencies managing many sites should add AcyMailing to their extension inventory and identify every Joomla installation that has not reached 11.1.0.

Joomla extension vulnerabilities: the confirmed SQL injection

The confirmed Joomla issue is CVE-2026-56292, an unauthenticated SQL injection vulnerability in the AcyMailing extension for Joomla. An unauthenticated issue is significant because an attacker would not need a Joomla account to attempt an attack. Depending on the site and database configuration, SQL injection can expose or extract information stored in the site database.

Available records identify the affected Joomla range as AcyMailing versions 6.0.0 and later, but before 10.11.1. The evidence does not establish whether versions before 6.0.0 are affected, so they should not be included in the confirmed range. The recommended fixed version is 10.11.1 or later; upgrading to 11.1.0 is the more practical target because it also includes the newer security-related changes.

The CVSS scores for this issue must be read with their scoring versions attached. The Joomla CNA score is CVSS 4.0: 9.2 Critical. The NVD record for CVE-2026-56292 also provides CVSS 3.1: 7.5 High. These are not competing reports or interchangeable values: they are assessments under different CVSS versions for the same vulnerability.

For Joomla administrators, the direct operational conclusion is simple: a site that was below 10.11.1 needs urgent remediation, and a site updated to 11.1.0 has moved beyond the confirmed vulnerable range while gaining the later hardening changes.

Product CVE Authentication Confirmed affected versions Recommended version CVSS CISA KEV status
AcyMailing extension for Joomla CVE-2026-56292 None required 6.0.0 and later, before 10.11.1 10.11.1 or later; use 11.1.0 or later CVSS 4.0: 9.2 Critical; CVSS 3.1: 7.5 High Not listed
AcyMailing plugin for WordPress CVE-2026-3614 Authenticated 9.11.0 through 10.8.1 10.8.2 or later CVSS 3.1: 8.8 High Not listed
AcyMailing plugin for WordPress CVE-2026-77807 None required Up to and including 11.0.4 11.0.5 or later CVSS 3.1: 7.5 High Not listed

Do not confuse Joomla and WordPress CVEs

AcyMailing is available for more than one content management system, and the product boundary matters. CVE-2026-56292 applies to the Joomla AcyMailing extension. The other two confirmed CVEs in this group apply to the WordPress AcyMailing plugin; they do not establish direct exposure for a Joomla AcyMailing installation.

WordPress CVE-2026-3614

CVE-2026-3614 is an authenticated privilege-escalation issue affecting WordPress AcyMailing versions 9.11.0 through 10.8.1. A missing authorization check could allow authenticated users with subscriber-level access or above to reach administrative functionality. The recommended update is version 10.8.2 or later. Its reported score is CVSS 3.1: 8.8 High.

The NVD status for this CVE is Deferred. That status means full NVD analysis is not currently available; it should not be described as a completed NVD assessment. WordPress owners should update, review autologin-related settings, and audit administrator accounts for unexpected changes.

WordPress CVE-2026-77807

CVE-2026-77807 is an unauthenticated arbitrary-file-read issue in the WordPress plugin, affecting versions up to and including 11.0.4 when the Embed images option is enabled. The recommended update is 11.0.5 or later, and its reported severity is CVSS 3.1: 7.5 High.

This CVE is also marked Deferred by NVD. WordPress teams should update to at least 11.0.5, disable image embedding where it is not required, and review server logs for unexpected file-access activity. These WordPress recommendations are included for organisations that operate both platforms; they are not a substitute for updating Joomla AcyMailing.

A practical update and verification checklist

For a Joomla site, the priority is to reach AcyMailing 11.1.0 or later safely and promptly. A well-managed update should preserve campaign delivery, subscriptions, forms, and any integration that depends on AcyMailing data.

  1. Identify the installed version. Record the AcyMailing version on every Joomla site, including staging, production, microsites, and client-managed installations. Treat any version below 10.11.1 as requiring immediate attention for CVE-2026-56292.
  2. Create restorable backups. Take and validate a current backup of the Joomla files and database before changing an extension. A backup is useful only when the responsible team can restore it within the site’s operational constraints.
  3. Test in staging where available. Update a representative staging copy first. Verify administrator access, subscription forms, campaigns, scheduled tasks, delivery settings, templates, and connected services that are relevant to the site.
  4. Update production to 11.1.0 or later. Confirm after installation that the expected version is active. Do not stop at an older version merely because it passes 10.11.1; the stated goal is to include the additional 11.1.0 security-related changes.
  5. Review configuration after the update. Confirm that only needed AcyMailing features remain enabled. Apply least privilege to Joomla administrator accounts, AcyMailing access, and the database account used by the site.
  6. Check normal site operation. Submit a controlled subscription test, verify expected confirmation and delivery behaviour, inspect the extension’s normal administrative views, and check Joomla and web-server logs for update errors.
  7. Document the result. For agency and compliance workflows, record the prior version, update date, backup location, validation checks, and any exceptions requiring follow-up.

The reported 11.1.0 fixes concern mailbox uploads and file fields, but the published information does not provide sufficient technical detail to prescribe feature-specific workarounds. Administrators should avoid treating unverified configuration advice as a replacement for the vendor update. If a site has custom AcyMailing add-ons, bespoke forms, or unusual mail-processing workflows, test those integrations carefully before and after deployment.

General defence in depth still applies: keep Joomla and all extensions maintained, restrict file and directory permissions appropriately for the hosting environment, use a database account with only the permissions the site needs, and retain tested backups. Those controls reduce the impact of many failures, but they do not replace patching a known vulnerable version.

Severity, exploitation and monitoring

Severity scoring and observed exploitation answer different questions. CVSS estimates the technical severity of a vulnerability under a particular scoring framework. Inclusion in CISA’s Known Exploited Vulnerabilities catalog is an indicator that exploitation has been observed and is sufficiently established for catalog inclusion. A high or critical CVSS rating does not, by itself, prove active exploitation.

None of the three CVEs discussed here—CVE-2026-3614, CVE-2026-56292, and CVE-2026-77807—is currently listed in the CISA Known Exploited Vulnerabilities catalog. There is also no authoritative confirmation in the available records that these issues are being actively exploited in the wild. There is no verified evidence connecting the 11.1.0 mailbox-upload or file-field changes to ransomware activity.

That status should lead to measured action, not complacency. CVE-2026-56292 is an unauthenticated Joomla SQL injection with a CVSS 4.0 Critical rating, and delayed extension maintenance unnecessarily preserves exposure. After upgrading, Joomla teams should review the period during which they were on an affected release. Look for unusual administrator or database activity through the monitoring and logs already available in the organisation, and follow the site’s incident-response process if credible indicators are found.

Continue to monitor AcyMailing release notes and the relevant CVE records. More information may later emerge about the 11.1.0 changes, while NVD entries currently marked Deferred for the WordPress CVEs may receive additional analysis. For Joomla sites, the immediate and evidence-based action remains unchanged: update AcyMailing to at least 11.1.0, validate the deployment, and keep the extension within a regular security-maintenance process.

References used

Add comment

By submitting a comment, you agree to our Comment Policy and Privacy Policy. Please keep comments respectful, relevant, and free from spam or promotional content. Your name and comment may be displayed publicly, while your email address will not normally be published. Technical information, including your IP address, may be processed for moderation, security, and spam prevention.

Submit