CVE-2026-40384 | Joomla CMS up to 5.4.5/6.1.0 File API Endpoint Search path traversal
A vulnerability, which was classified as critical, was found in Joomla CMS up to 5.4.5/6.1.0. The impacted element is an unknown function of the component File API Endpoint. The manipulation of the argument Search results in path traversal.
This vulnerability is cataloged as CVE-2026-40384. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.