CVE-2026-48957: Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
Published Jul 7, 2026
·Updated
An improper access check allows unauthorized users to access comprivacy datasets.
Affected Software
3 affected components
Joomla! Joomla! Core=20260711
Joomla Joomla\!>=4.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48957?
CVE-2026-48957 has a risk score of 52, indicating a moderate security vulnerability.
2
What issue does CVE-2026-48957 represent?
CVE-2026-48957 represents an incorrect access control vulnerability in Joomla!'s com_privacy webservice endpoints.
3
Who is affected by CVE-2026-48957?
Users of Joomla! Core with access to the com_privacy component may be affected by CVE-2026-48957.
4
How do I fix CVE-2026-48957?
To fix CVE-2026-48957, update Joomla! to the latest version that addresses this incorrect access control vulnerability.
5
What can happen if CVE-2026-48957 is exploited?
If exploited, CVE-2026-48957 allows unauthorized users to access sensitive com_privacy datasets.