Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.4
CVE-2026-48948: Joomla! Core - Users Can Download Inaccessible Contact Data
CVE-2026-48948
CVE-2026-48948
BIT-joomla-2026-48948
Summary
A security issue in Joomla!'s contact manager allows users to download contact information that they shouldn't have access to. This can lead to sensitive information being exposed to unauthorized individuals. To protect your site, update Joomla! to the latest version or apply the recommended fix.
What to do
- Update joomla to version 6.1.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | joomla! project | joomla! cms | 3.0.0-5.4.6 |
| – | joomla | joomla\! |
>= 3.0.0, < 5.4.7 >= 6.0.0, < 6.1.2 cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
| Bitnami | – | joomla |
>= 6.0.0, < 6.1.2 Fix: upgrade to 6.1.2
|
Original title
Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
Original description
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
nvd CVSS4.0
6.4
Vulnerability type
CWE-284
Improper Access Control
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 7 Jul 2026