Executive brief
K2 is a popular content management extension for Joomla that provides enhanced article and user profile features. A security flaw allows registered users to modify hidden parts of their own profile data that are normally restricted. This could allow a user to change their profile image, notes, or plugin settings in ways the website administrator did not intend.
Technical details
A mass-assignment (CWE-915) defect exists in the K2 system user plugin `plg_user_k2` for Joomla. By injecting the `K2UserForm=1` field into a standard `com_users` `profile.save` POST request, an authenticated 'Registered' user can bypass frontend form restrictions. This allows the attacker to write arbitrary values into the `notes`, `image`, and `plugins` columns of their own record in the `#__k2_users` database table. These fields are not intended to be user-editable via the standard K2 frontend profile-edit form.
Affected products
- JoomlaWorks K2 extension for Joomla 1.0-2.26
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory