Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla workflow access flaw fixed in version 6.1.2

Administrators running Joomla! CMS 6.0.0-6.1.1 should upgrade to 6.1.2 to address a Moderate Incorrect Access Control vulnerability in com_workflow, tracked as CVE-2026-48955.

The Joomla project’s advisory describes an authorization failure in com_workflow, the component responsible for workflow features. Under certain conditions, an unauthorized user could obtain information about workflow stages and transitions.

The issue is classified as follows:

  • Exploit type: Incorrect Access Control
  • Severity: Moderate
  • Probability: Low
  • Impact: Moderate
  • CVE: CVE-2026-48955

The affected release range is Joomla! CMS 6.0.0-6.1.1. The project lists 6.1.2 as the solution, so site owners should review their installed version and apply the update through their normal Joomla maintenance process. Developers and administrators who manage workflow-based sites should also check whether access to stage or transition information may have been exposed before the update was applied.

The vulnerability was reported on 2026-04-22 by 廖双. The Joomla Security Centre lists 2026-07-07 as the fixed date and directs further enquiries to the JSST.

Published by the Joomla Security Centre.