On July 30, 2026, Akeeba Ltd released updates for their key products: Akeeba Backup for Joomla (10.3.7), Akeeba Solo (9.1.8), and Admin Tools for Joomla (7.9.0). The primary focus of these releases is security hardening.

The developers emphasize that the discovered issues could not lead to site compromise in the default configuration, where only Super Administrators have access to the components. However, in non-standard setups where access is delegated to less privileged users, there were risks that have now been addressed.

What Was Fixed?

Access Control Fixes

By default, all Akeeba products are accessible only to Joomla Super Administrators or WordPress Administrators. However, developers discovered several issues in the permission checking mechanisms:

  • In Akeeba Backup several pages (Schedule, Statistics, Profile management, and backup deletion) were not properly enforcing access privileges. Any user with general component access could reach them. This gap is now closed, and access to the Schedule page, which may display API secrets, is additionally restricted.
  • In Akeeba Solo a similar issue affected user and profile management pages — internal access checks could fail for certain pages. This has been fixed.
  • In Admin Tools issues of both types were found: some pages required stricter permissions than needed (users couldn't access despite delegated access), while others were too permissive, allowing limited operators to create temporary Super Administrator accounts.

Improved CSRF Protection

A CSRF (Cross-Site Request Forgery) attack can trick an authenticated user's browser into performing an unwanted action without their knowledge. During the audit, gaps in CSRF token validation were found and fixed.

All actions requiring confirmation are now better protected. The developers note that even in the worst case, an attacker could trick a user into deleting an offsite backup archive or cleaning the temporary folder — which would inconvenience the site owner rather than help the attacker.

New Security Features in Admin Tools 7.9.0

Admin Tools for Joomla now includes important new capabilities:

  • UploadShield (reintroduced): This feature scans uploaded files for PHP code, hidden extensions, and attempts to bypass .htaccess protection. It now works regardless of how third-party extension developers handle file uploads. This significantly complicates file-upload-based attacks. Important: when enabled, only Super Administrators will be able to upload .php files to the site.
  • PHP File Change Scanner: The scanner can now verify Joomla core files against checksums, making it easier to detect modified (compromised) files.
  • Configuration Monitoring with Change Diffs: Configuration change notifications now show exactly what changed (with sensitive values masked). This allows quick assessment of changes to global configuration or component settings.
  • Improved SQLiShield and PHPShield: Improved protection against SQL injection and attempts to bypass PHP stream wrappers (e.g., php://filter) for reading source code. PHPShield fixed a bug that allowed bypassing protection by adding whitespace before an attack.

Who Is at Risk?

Sites are at risk if they meet the following conditions:

  • Running vulnerable versions of Akeeba components: Akeeba Backup for Joomla (up to 10.3.7), Akeeba Backup for WordPress (up to 9.1.8), Akeeba Solo (up to 9.1.8), or Admin Tools for Joomla (up to 7.9.0).
  • Non-standard configuration with delegated access to these components for users who are not Super Administrators. Only in such cases could the vulnerabilities be exploited.

If you have never changed access settings and have only allowed Super Administrators to manage Akeeba Backup or Admin Tools, your risk was minimal, but you should still update for overall security.

How to Fix It: Step-by-Step Instructions

To address the vulnerabilities and benefit from new security features, follow the steps below.

Step 1: Update Akeeba Components

  1. Create a backup of your site and database.
  2. For Joomla: Go to Extensions → Manage → Update, click "Purge Cache" and "Find Updates". Install updates for Akeeba Backup (10.3.7) and Admin Tools (7.9.0).
  3. For WordPress: Update Akeeba Backup for WordPress to version 9.1.8 through the admin panel Plugins → Installed or by downloading the new version from the developer's site. Akeeba Backup for WordPress is distributed only through the official developer website; it is not available in the WordPress repository.

If the update does not appear:
Download the latest versions manually from the official Akeeba Ltd website akeeba.com and install through the standard Joomla or WordPress extension installer.

Step 2: Review Access Settings

After updating, we recommend reviewing your access policy for Akeeba components:

  • Restrict access to Super Administrators (Joomla) or Administrators (WordPress). This is the standard and most secure configuration.
  • If access delegation is necessary, review the permissions granted to each user or role and ensure they do not exceed the minimum required.

Step 3: Configure New Admin Tools Features (for Joomla)

For Admin Tools users:

  1. Enable UploadShield: In the component settings, find the Web Application Firewall (WAF) section and enable the updated UploadShield. Note that this may restrict PHP file uploads for all except Super Administrators.
  2. Enable configuration monitoring with change diffs: In the WAF settings, activate configuration change notifications. Emails will now include details of what parameters changed.
  3. Configure the core file scanner: Enable Joomla core file checksum verification for early detection of compromised files.
  4. Update email notification templates: If you previously configured configuration monitoring notification templates, add the placeholders {INFO} (for text version) and {INFO_HTML} (for HTML version) to receive change details. This can be done in the System → Email Templates section in Joomla.

Recommendation

Updating Akeeba components is an important step in maintaining your site's security. While the found vulnerabilities were not critical for most standard installations, they highlight the importance of regular updates and careful attention to access delegation. The new Admin Tools features, such as UploadShield and improved monitoring, significantly enhance overall protection and help respond faster to compromise attempts.

Important!
If your site has been hacked and you are unsure what to do, or have any doubts, contact us immediately for assistance! We will help conduct an audit, clean your site of hidden threats, and restore its functionality.

Submit a request List of services

Terms used:

Akeeba Backup, Core, HTML, PHP, SQL, Backup