Executive brief
Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in its workflow management component. This vulnerability allows users who should not have permission to view internal details about how content moves through different stages of approval and publication. While it does not allow for the modification of content, it exposes administrative process information that could be used to understand internal business logic.
Technical details
An improper access control vulnerability (CWE-284) exists within the 'com_workflow' component of Joomla! CMS. The flaw is rooted in an inadequate access check that fails to properly restrict visibility of workflow stages and transitions. A remote attacker with high privileges (PR:H) can exploit this over the network to gain unauthorized access to metadata regarding the site's internal content management processes. The vulnerability affects versions 6.0.0 through 6.1.1 and has been addressed in version 6.1.2.
Affected products
- Joomla! Project Joomla! CMS 6.0.0-6.1.1
Timeline
- 2026-04-22: other: Reported date
- 2026-07-07: patched: Fixed in version 6.1.2
- 2026-07-07: disclosed: Public advisory published