Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.4
CVE-2026-48958: Joomla! Core - Unauthorized Custom Field Creation
CVE-2026-48958
CVE-2026-48958
BIT-joomla-2026-48958
Summary
The Joomla! core is vulnerable to a security issue that allows anyone to create custom fields without proper permission. This can lead to data tampering and unauthorized changes to the website. To fix this, update to the latest version of Joomla!
What to do
- Update joomla to version 6.1.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | joomla! project | joomla! cms | 4.0.0-5.4.6 |
| – | joomla | joomla\! |
>= 4.0.0, < 5.4.7 >= 6.0.0, < 6.1.2 cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* |
| Bitnami | – | joomla |
>= 6.0.0, < 6.1.2 Fix: upgrade to 6.1.2
|
Original title
Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
Original description
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Vulnerability type
CWE-284
Improper Access Control
Published: 12 Jul 2026 · Updated: 17 Jul 2026 · First seen: 7 Jul 2026