CVE-2026-48943: Joomla Extension - getk2.org - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin plguserk2. A Registered Joomla user, by including the field K2UserForm=1 in a standard comusers profile.save POST, can write arbitrary values into the notes, image, and plugins columns of their own row in the #k2users table — none of which are exposed by the K2 frontend profile-edit form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48943?
CVE-2026-48943 has a medium severity rating of 6.5 according to the CVSS v3.1 metrics.
How do I fix CVE-2026-48943?
To mitigate CVE-2026-48943, update the K2 extension to version 2.26 or later.
Who is affected by CVE-2026-48943?
All Joomla users utilizing K2 extension versions 2.24 and below are affected by CVE-2026-48943.
What is the risk associated with CVE-2026-48943?
CVE-2026-48943 presents a risk level of 40, which indicates a potential for exploitation if not addressed.
Can an attacker exploit CVE-2026-48943 without authentication?
No, the exploitation of CVE-2026-48943 requires an authenticated Joomla user to perform the attack.