Junglewise Threat Intelligence

CVE-2026-48948: Joomla! CMS improper access control in com_contact vCard download

CVE-2026-48948 · Severity: info · CVSS 6.4 · Published 2026-07-07

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

Joomla! CMS, a popular website management platform, contains a security flaw in its contact management component. This vulnerability allows users with high-level permissions to download contact information (vCards) that they should not be able to access. This could lead to the unauthorized exposure of personal or professional contact details stored within the system.

Technical details

An improper access control vulnerability (CWE-284) exists in the Joomla! CMS 'com_contact' component. The root cause is a failure to correctly validate user permissions during the vCard (.vcf) download process. An attacker with high privileges (PR:H) can exploit this over the network to export contact data that is otherwise restricted or inaccessible to them. The vulnerability affects Joomla! versions 3.0.0 through 5.4.6 and 6.0.0 through 6.1.1. Users are advised to upgrade to versions 5.4.7 or 6.1.2 to remediate the issue.

Affected products

  • Joomla! Project Joomla! CMS 3.0.0 - 5.4.6, 6.0.0 - 6.1.1

Timeline

  • 2026-05-07: other: Reported date
  • 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
  • 2026-07-07: disclosed: Public disclosure of CVE-2026-48948

References

Related threats