Security
Joomla fixes access control flaw in contact vCard downloads
Administrators running Joomla! CMS versions 3.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Low-severity Incorrect Access Control issue in com_contact.
The Joomla project says the flaw could allow a user to download vCard exports for contacts that should be inaccessible to them. The issue is tracked as CVE-2026-48948.
The advisory rates both the impact and probability as Low. It concerns Joomla!'s contact component and specifically affects the vCard download functionality, where an improper access check could expose contact data through an export request.
- Exploit type:
Incorrect Access Control - Fixed versions:
5.4.7and6.1.2 - Affected Installs:
3.0.0-5.4.5and6.0.0-6.1.1
The source's Versions field lists 3.0.0-5.4.6 and 6.0.0-6.1.1, while its Affected Installs field lists the first range through 5.4.5. Administrators should follow the stated upgrade guidance and move to the fixed release for their branch.
Published by the Joomla Security Centre.