Junglewise Threat Intelligence

CVE-2026-48957: Joomla! CMS improper access control in com_privacy webservice endpoints

CVE-2026-48957 · Severity: info · CVSS 6.4 · Published 2026-07-07

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

Joomla! CMS, a popular website management platform, contains a security flaw in its privacy management component. This vulnerability could allow unauthorized users to access sensitive privacy-related datasets through specific web service endpoints. If exploited, this could lead to the exposure of user data or internal privacy records, potentially impacting regulatory compliance and user trust.

Technical details

An improper access control vulnerability (CWE-284) exists within the com_privacy web service endpoints of Joomla! CMS. The root cause is a failure to perform adequate access checks, which allows users who should not have permission to retrieve privacy datasets. The attack is network-reachable and requires high privileges (PR:H) to execute, but it can lead to a loss of confidentiality for sensitive privacy information. The vulnerability affects Joomla! versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1. Users are advised to upgrade to versions 5.4.7 or 6.1.2 to remediate the issue.

Affected products

  • Joomla! Project Joomla! CMS 4.0.0-5.4.6, 6.0.0-6.1.1

Timeline

  • 2026-06-12: other: Reported to vendor
  • 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
  • 2026-07-07: advisory: Public advisory released

References