
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48955 is an improper access control vulnerability in Joomla! CMS that allows unauthorized users to access workflow stage and transition information. It affects Joomla! versions 6.0.0 through 6.1.1, and was published on July 7, 2026, with a patch advisory released on July 9, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 6.4 (Medium) (GitHub Advisory, Joomla Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control) and resides in Joomla!'s com_workflow component. An insufficient access check allows authenticated or unauthenticated users to retrieve workflow stage and transition data that should be restricted to authorized roles. Exploitation requires network access and low attack complexity, with no user interaction needed; the CVSS v3.1 scoring indicates low privileges are required, while the CVSS v4.0 vector reflects high privileges required for the vulnerable system itself (GitHub Advisory, Joomla Advisory).
Successful exploitation results in unauthorized disclosure of workflow stage and transition information, representing a high confidentiality impact on subsequent systems per the CVSS v4.0 assessment. There is no direct integrity or availability impact on the vulnerable system itself, but exposure of workflow configuration details could assist attackers in understanding internal content management processes and planning further targeted actions. The scope is limited to information disclosure within the Joomla! CMS workflow subsystem (GitHub Advisory, Joomla Advisory).
Joomla! has released a patch addressing this vulnerability; users should upgrade to Joomla! 6.1.2 or later, which is the first version excluding the affected range of 6.0.0–6.1.1 (Joomla Advisory). As an interim measure, administrators should review and restrict access controls for workflow-related functionality within the Joomla! backend and monitor access logs for unauthorized requests to workflow endpoints. No specific configuration-based workaround has been published beyond applying the official patch.
The vulnerability received routine coverage from vulnerability tracking services including VulDB, Tenable, and ENISA's EUVD shortly after disclosure. Italy's GARR CERT issued a security alert referencing the Joomla! update. No significant researcher commentary or notable social media discussion beyond automated CVE notification accounts has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."