CVE-2026-48941: Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension for Joomla < 2.26
Published Jun 25, 2026
·Updated
The K2 frontend item.checkin task accepts an unauthenticated sigProFolder query parameter and uses it directly to address a JFolder::delete() call under /media/k2/galleries/
Affected Software
2 affected components
Joomla K2 extension<2.26
JoomlaWorks K2 Joomla\!<=2.26
Event History
Jun 25, 2026
CVE Published
via MITRE·03:25 PM
Data Sourced
via MITRE·03:25 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48941?
The severity of CVE-2026-48941 is classified as medium with a score of 6.5.
2
How do I fix CVE-2026-48941?
To fix CVE-2026-48941, upgrade the K2 extension for Joomla to version 2.26 or later.
3
What systems are affected by CVE-2026-48941?
CVE-2026-48941 affects Joomla sites using the K2 extension version less than 2.26.
4
What type of vulnerability is CVE-2026-48941?
CVE-2026-48941 is an unauthenticated folder deletion vulnerability in the K2 extension.
5
What impact does CVE-2026-48941 have?
CVE-2026-48941 can lead to unauthorized deletion of files from the Joomla media galleries.