
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48957 is an improper access control vulnerability in the Joomla! CMS com_privacy component that allows unauthorized users to access privacy-related datasets via webservice endpoints. It affects Joomla! versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1, with fixes available in versions 5.4.7 and 6.1.2. The vulnerability was published on July 7, 2026, with the official Joomla! security advisory released on July 11, 2026. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 6.4 (Medium) (GitHub Advisory, Joomla Advisory).
The root cause is classified as CWE-284 (Improper Access Control), where the com_privacy component's webservice endpoints fail to properly verify whether a requesting user has the necessary permissions before returning privacy-related data. An attacker can exploit this by sending crafted HTTP requests to the affected webservice endpoints without holding the required authorization level. The attack is network-based, requires low complexity, and — per the CVSS v3.1 scoring — requires only low-level privileges, though the CVSS v4.0 assessment rates privileges required as high, suggesting some ambiguity in the exact preconditions. No public proof-of-concept code has been identified (GitHub Advisory, Joomla Advisory).
Successful exploitation allows unauthorized actors to read sensitive data stored in the Joomla! com_privacy component, which typically contains user privacy request records and related personal information. Under the CVSS v4.0 model, the subsequent system impact is rated High for confidentiality, integrity, and availability, suggesting that access to this data could facilitate further compromise of dependent systems or data. The primary risk is unauthorized disclosure of privacy-sensitive user data managed by the CMS (GitHub Advisory, Joomla Advisory).
com_privacy webservice API endpoints (e.g., /api/index.php/v1/privacy/...) from unauthenticated or low-privileged user sessions.com_privacy endpoints from accounts that should not have access; anomalous API calls returning HTTP 200 responses for privacy data without corresponding authorized sessions.Joomla! has released patched versions 5.4.7 (for the 4.x/5.x branch) and 6.1.2 (for the 6.x branch); upgrading to these versions is the primary recommended remediation. As an interim measure, administrators should restrict access to com_privacy webservice endpoints via web server configuration (e.g., blocking API routes at the firewall or WAF level) and review access control settings within Joomla!'s user permission configuration. Reviewing logs for unauthorized access to privacy components is also advised while awaiting patch deployment (Joomla Advisory, GitHub Advisory).
The vulnerability received routine coverage from vulnerability tracking services including VulDB, CVEFeed, and CIRCL shortly after disclosure. The Italian GARR CERT issued a security alert (GCSA-26117) recommending Joomla! updates. No notable researcher commentary or significant social media discussion beyond automated CVE notification accounts has been identified (GARR CERT Alert).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."