Executive brief
Joomla! CMS, a popular website management platform, contains a security flaw in its privacy management component. This vulnerability could allow unauthorized users to access sensitive privacy-related datasets through specific web service endpoints. If exploited, this could lead to the exposure of user data or internal privacy records, potentially impacting regulatory compliance and user trust.
Technical details
An improper access control vulnerability (CWE-284) exists within the com_privacy web service endpoints of Joomla! CMS. The root cause is a failure to perform adequate access checks, which allows users who should not have permission to retrieve privacy datasets. The attack is network-reachable and requires high privileges (PR:H) to execute, but it can lead to a loss of confidentiality for sensitive privacy information. The vulnerability affects Joomla! versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1. Users are advised to upgrade to versions 5.4.7 or 6.1.2 to remediate the issue.
Affected products
- Joomla! Project Joomla! CMS 4.0.0-5.4.6, 6.0.0-6.1.1
Timeline
- 2026-06-12: other: Reported to vendor
- 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
- 2026-07-07: advisory: Public advisory released