Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.4

CVE-2026-48948: Joomla! Core - Users Can Download Inaccessible Contact Data

CVE-2026-48948 CVE-2026-48948 BIT-joomla-2026-48948
Summary

A security issue in Joomla!'s contact manager allows users to download contact information that they shouldn't have access to. This can lead to sensitive information being exposed to unauthorized individuals. To protect your site, update Joomla! to the latest version or apply the recommended fix.

What to do
  • Update joomla to version 6.1.2.
Affected software
Ecosystem VendorProductAffected versions
joomla! project joomla! cms 3.0.0-5.4.6
joomla joomla\! >= 3.0.0, < 5.4.7
>= 6.0.0, < 6.1.2
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Bitnami joomla >= 6.0.0, < 6.1.2
Fix: upgrade to 6.1.2
Original title
Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
Original description
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
nvd CVSS4.0 6.4
Vulnerability type
CWE-284 Improper Access Control
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 7 Jul 2026