Security
Joomla fixes access control flaw in com_privacy endpoints
Joomla administrators running 4.0.0-5.4.6 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2, respectively, to fix CVE-2026-48957 in com_privacy webservice endpoints.
The Joomla project classifies this issue as an Incorrect Access Control vulnerability with Moderate severity and Low probability. It affects Joomla! CMS installations using the listed version ranges.
The flaw involves an improper access check that can let unauthorized users access datasets exposed through com_privacy. Site administrators should apply the appropriate update rather than relying on endpoint restrictions or user permissions as a workaround.
- Exploit type: Incorrect Access Control
- Impact: Low
- CVE:
CVE-2026-48957 - Fixed versions:
5.4.7and6.1.2
The Joomla Security Strike Team received the report from Himanshu Anand on 2026-06-12. The project marked the issue fixed on 2026-07-07.
Published by the Joomla Security Centre.