CVE-2026-48958
published 2026-07-07CVE-2026-48958: An improper access check allows unauthorized users to create custom fields via webservices endpoints.
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.46%
39.2th percentile
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_cms | — | — |
| joomla | joomla_! | >= 4.0.0 < 5.4.7 | 5.4.7 |
| joomla | joomla_! | >= 6.0.0 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.4MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Joomla! Project Joomla! CMS improper authorization (EUVD-2026-42068 / Nessus ID 325458)
vuldb·2026-07-07·CVSS 6.4
CVE-2026-48958 [MEDIUM] Joomla! Project Joomla! CMS improper authorization (EUVD-2026-42068 / Nessus ID 325458)
A vulnerability, which was classified as critical, has been found in Joomla! Project Joomla! CMS. This impacts an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-48958. The attack can be initiated remotely. There is not any exploit available.
GHSA
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
ghsa_unreviewed·2026-07-07
CVE-2026-48958 [MEDIUM] CWE-284 An improper access check allows unauthorized users to create custom fields via webservices endpoints.
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-07
Published