Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.4
CVE-2026-48957: Joomla! Comprises Unauthorized Data Access
CVE-2026-48957
CVE-2026-48957
BIT-joomla-2026-48957
Summary
An improper access check in Joomla!'s com_privacy module allows unauthorized users to view sensitive data. This is a serious security risk as it can lead to data exposure. To protect your site, update Joomla! to the latest version or apply the provided patch.
What to do
- Update joomla to version 6.1.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | joomla! project | joomla! cms | 4.0.0-5.4.6 |
| – | joomla | joomla\! |
>= 4.0.0, < 5.4.7 >= 6.0.0, < 6.1.2 cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
| Bitnami | – | joomla |
>= 6.0.0, < 6.1.2 Fix: upgrade to 6.1.2
|
Original title
Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
Original description
An improper access check allows unauthorized users to access com_privacy datasets.
nvd CVSS4.0
6.4
Vulnerability type
CWE-284
Improper Access Control
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 7 Jul 2026