CVE-2026-48948: Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
Published Jul 7, 2026
·Updated
An improper access check allows user to download vcard exports of comcontact contacts that are inaccessible.
Affected Software
3 affected components
Joomla! Joomla! Core
Joomla Joomla\!>=3.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48948?
The severity of CVE-2026-48948 is rated at 37.
2
How do I fix CVE-2026-48948?
To fix CVE-2026-48948, ensure that proper access controls are implemented for the com_contact component.
3
What software is affected by CVE-2026-48948?
CVE-2026-48948 affects Joomla! Core, specifically the com_contact component.
4
What type of vulnerability is CVE-2026-48948?
CVE-2026-48948 is an incorrect access control vulnerability that allows unauthorized users to download inaccessible vCard exports.
5
When was CVE-2026-48948 published?
CVE-2026-48948 was published on July 7, 2026.