
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48956 is an improper access control vulnerability in Joomla! CMS that allows authenticated users to display a list of active frontend modules without proper authorization. It affects Joomla! versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1, with fixed versions being 5.4.7 and 6.1.2 respectively. The vulnerability was published on July 7, 2026, and is classified as Moderate severity with a CVSS v3.1 base score of 5.0 and a CVSS v4.0 base score of 6.4 (GitHub Advisory, Joomla Security).
The root cause is classified as CWE-284 (Improper Access Control), specifically within the com_modules component of Joomla!'s frontend. The access check governing module list visibility is insufficiently enforced, allowing a low-privileged authenticated user to enumerate active frontend modules that should be restricted. Exploitation requires network access and a valid low-privilege account, but no special conditions or user interaction beyond authentication (GitHub Advisory, Joomla Security).
Successful exploitation exposes the list of active frontend modules to unauthorized users, revealing information about the site's configuration, installed extensions, and module layout. This information can aid attackers in reconnaissance, helping them identify potentially vulnerable or misconfigured components for follow-on attacks. There is no direct impact on integrity or availability of the vulnerable system itself, though the CVSS v4.0 scoring reflects a high subsequent system impact due to the reconnaissance value of the exposed data (GitHub Advisory, Joomla Security).
com_modules component endpoint that lists frontend modules, bypassing the insufficient access check.com_modules (e.g., URLs containing option=com_modules) from authenticated low-privilege user sessions.index.php?option=com_modules or similar patterns from non-administrator accounts.Joomla! has released patched versions 5.4.7 (for the 4.x/5.x branch) and 6.1.2 (for the 6.x branch); administrators should upgrade immediately (Joomla Security). As a temporary workaround if patching is not immediately possible, review and restrict frontend module visibility settings and implement WAF rules to block unauthorized access to module enumeration endpoints. Limiting frontend user registration and enforcing the principle of least privilege for user accounts can also reduce exposure.
The vulnerability was noted by automated CVE tracking services and security aggregators including VulDB, CVEFeed, and CERT GARR (Italy), which issued a security alert for Joomla! (CERT GARR). Tenable added detection support via pipeline and WAS plugins shortly after disclosure. No significant researcher commentary or social media debate has been observed beyond routine CVE tracking activity.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."