Executive brief
Joomla! CMS, a popular website management platform, contains a security flaw in its contact management component. This vulnerability allows users with high-level permissions to download contact information (vCards) that they should not be able to access. This could lead to the unauthorized exposure of personal or professional contact details stored within the system.
Technical details
An improper access control vulnerability (CWE-284) exists in the Joomla! CMS 'com_contact' component. The root cause is a failure to correctly validate user permissions during the vCard (.vcf) download process. An attacker with high privileges (PR:H) can exploit this over the network to export contact data that is otherwise restricted or inaccessible to them. The vulnerability affects Joomla! versions 3.0.0 through 5.4.6 and 6.0.0 through 6.1.1. Users are advised to upgrade to versions 5.4.7 or 6.1.2 to remediate the issue.
Affected products
- Joomla! Project Joomla! CMS 3.0.0 - 5.4.6, 6.0.0 - 6.1.1
Timeline
- 2026-05-07: other: Reported date
- 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
- 2026-07-07: disclosed: Public disclosure of CVE-2026-48948