CVE-2026-48901: Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects
Published May 26, 2026
·Updated
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=4.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48901?
CVE-2026-48901 has a severity rating of 7.5, categorized as high.
2
How do I fix CVE-2026-48901?
To fix CVE-2026-48901, update your Joomla! installation to the latest version that addresses this vulnerability.
3
What does CVE-2026-48901 affect?
CVE-2026-48901 affects Joomla Core, specifically the InputFilter objects.
4
What is the risk associated with CVE-2026-48901?
The risk associated with CVE-2026-48901 is assessed at a moderate level of 43.
5
What is the main issue described in CVE-2026-48901?
CVE-2026-48901 describes an incorrect cache key construction for InputFilter objects in Joomla! that omits a security-sensitive parameter.