A vulnerability classified as critical was found in Joomla CMS up to 5.4.5/6.1.0. This affects an unknown function. The manipulation results in path traversal.

This vulnerability is identified as CVE-2026-40383. The attack is only possible with local access. There is not any exploit available.

Upgrading the affected component is advised.