CVE-2026-48957
Analyzed Analyzed - Analysis Complete

Improper Access Check in Joomla com_privacy

Vulnerability report for CVE-2026-48957, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-07

Last updated on: 2026-07-09

Assigner: Joomla! Project

Description

An improper access check allows unauthorized users to access com_privacy datasets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-07
Last Modified
2026-07-09
Generated
2026-07-11
AI Q&A
2026-07-08
EPSS Evaluated
2026-07-09
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
joomla joomla! From 6.0.0 (inc) to 6.1.2 (exc)
joomla joomla! From 4.0.0 (inc) to 5.4.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Detection Guidance

This vulnerability involves incorrect access control in the com_privacy webservice endpoints of Joomla! CMS, allowing unauthorized access to com_privacy datasets.

To detect this vulnerability on your system, you should verify the Joomla! CMS version in use. Versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1 are affected.

There are no specific detection commands provided in the available resources. However, general steps include checking the Joomla! version and testing access to com_privacy webservice endpoints without proper authorization.

  • Check Joomla! version via command line or admin interface to confirm if it falls within the vulnerable versions.
  • Attempt to access com_privacy webservice endpoints without authentication to see if unauthorized access is possible.

For precise detection methods or commands, contacting the Joomla! Security Centre (JSST) is recommended.

Executive Summary

CVE-2026-48957 is a security vulnerability in Joomla! CMS versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1. It involves incorrect access control in the com_privacy webservice endpoints, which allows unauthorized users to access com_privacy datasets.

This means that users who should not have permission can view or retrieve sensitive privacy-related data due to improper access checks.

Impact Analysis

The vulnerability can lead to unauthorized access to sensitive privacy datasets within Joomla! CMS, potentially exposing personal or confidential information.

This exposure can compromise user privacy and data security, increasing the risk of data breaches or misuse of information.

Users of affected Joomla! CMS versions are advised to upgrade to versions 5.4.7 or 6.1.2 to mitigate this risk.

Mitigation Strategies

To mitigate the vulnerability CVE-2026-48957, users should upgrade Joomla! CMS to versions 5.4.7 or 6.1.2, where the issue has been fixed.

If further assistance is needed, contacting the Joomla! Security Centre (JSST) is recommended.

Compliance Impact

The vulnerability allows unauthorized users to access com_privacy datasets due to improper access checks in Joomla! CMS. This unauthorized access to privacy-related data could potentially lead to non-compliance with data protection regulations such as GDPR and HIPAA, which require strict controls over access to personal and sensitive information.

Organizations using affected Joomla! CMS versions should upgrade to the fixed versions to mitigate the risk of unauthorized data access and maintain compliance with relevant privacy and security standards.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48957. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart