Improper access control in Joomla! - CVE-2026-48899

 

Improper access control in Joomla! - CVE-2026-48899

Published: May 26, 2026


Vulnerability identifier: #VU132330
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48899
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform unauthorized actions related to the installation of sample data.

The vulnerability exists due to improper access control in sample data plugins when handling installation actions for sample data. A remote attacker can invoke sample data installation functionality to perform unauthorized actions related to the installation of sample data.


Affected software

Joomla!

How to mitigate CVE-2026-48899

Install security update from vendor's website.

Joomla! - addressed in versions 5.4.6, 6.1.1

External References

Related Security Bulletins