Executive brief
Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in how it handles access permissions for site modules. An attacker with high-level administrative privileges can bypass intended restrictions to view a list of installed modules on the public-facing side of the website. While this does not directly allow for data theft, it exposes information about the site's configuration that could be used to plan further attacks.
Technical details
An improper access control vulnerability exists in the com_modules component of Joomla! CMS. The flaw is rooted in an inadequate access check that fails to properly restrict the display of module lists on the frontend. A network-based attacker with high privileges (PR:H) can exploit this to enumerate installed modules. The vulnerability affects Joomla! versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1. Users are advised to upgrade to versions 5.4.7 or 6.1.2 to remediate the issue.
Affected products
- Joomla! Project Joomla! CMS 4.0.0 - 5.4.6, 6.0.0 - 6.1.1
Timeline
- 2026-05-22: other: Reported to vendor
- 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
- 2026-07-07: disclosed: CVE published