Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.4

CVE-2026-48958: Joomla! Core - Unauthorized Custom Field Creation

CVE-2026-48958 CVE-2026-48958 BIT-joomla-2026-48958
Summary

The Joomla! core is vulnerable to a security issue that allows anyone to create custom fields without proper permission. This can lead to data tampering and unauthorized changes to the website. To fix this, update to the latest version of Joomla!

What to do
  • Update joomla to version 6.1.2.
Affected software
Ecosystem VendorProductAffected versions
joomla! project joomla! cms 4.0.0-5.4.6
joomla joomla\! >= 4.0.0, < 5.4.7
>= 6.0.0, < 6.1.2
cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:*
Bitnami joomla >= 6.0.0, < 6.1.2
Fix: upgrade to 6.1.2
Original title
Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
Original description
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Vulnerability type
CWE-284 Improper Access Control
Published: 12 Jul 2026 · Updated: 17 Jul 2026 · First seen: 7 Jul 2026