Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes module access-control flaw

Joomla CMS sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 should be upgraded to 5.4.7 or 6.1.2 to address a Moderate-severity access-control issue.

The Joomla project has assigned CVE-2026-48956 to an issue in the com_modules component. Its exploit type is Incorrect Access Control, with a Moderate impact, Moderate severity and Low probability.

The affected Joomla CMS releases are:

  • 4.0.0-5.4.6
  • 6.0.0-6.1.1

According to the advisory, an improper access check can allow users to display a list of modules in the frontend. The behaviour concerns visibility of the module listing; the announcement does not describe a route to modify module content or configuration.

Administrators should update installations in the affected ranges to 5.4.7 for the 4.x and 5.x line, or 6.1.2 for the 6.x line. The project credits Warisjeet Singh (sin99xx) with reporting the issue. Sites that cannot update immediately should review frontend access and module-management permissions, although the advisory does not specify a workaround.

Published by the Joomla Security Centre.