Junglewise Threat Intelligence

CVE-2026-48958: Joomla! CMS improper access control in com_fields webservice

CVE-2026-48958 · Severity: info · CVSS 6.4 · Published 2026-07-07

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

Joomla! CMS is a popular platform used to build and manage websites. A security flaw in its web services interface allows users without proper permissions to create custom data fields. While this requires high-level account access, it could allow an attacker to modify the site's data structure or interfere with administrative operations.

Technical details

An incorrect access control vulnerability (CWE-284) exists within the com_fields component's webservice endpoints in Joomla! CMS. The root cause is an improper access check that fails to adequately verify user permissions before allowing the creation of custom fields. An attacker with high-privileged network access can exploit this to inject unauthorized fields into the system. The vulnerability affects versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1, and has been patched in versions 5.4.7 and 6.1.2.

Affected products

  • Joomla! Project Joomla! CMS 4.0.0 - 5.4.6, 6.0.0 - 6.1.1

Timeline

  • 2026-05-05: other: Reported to vendor
  • 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
  • 2026-07-07: disclosed: NVD publication date

References

Related threats