CVE-2026-48958
Incorrect Access Control in com_fields webservice endpoints
MEDIUM
Joomla CMS
Source officielle
Description
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Source officielle Description du Joomla Security Centre (Joomla).
Sévérité
—
Moyenne
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| Joomla Security Centre | Moderate | — |
| CERT-FR (ANSSI) | — | — |
Produit et versions
- Produit
- Joomla CMS
- Corrigée dans
- 5.4.7, 6.1.2
- Publiée
- 07/07/2026
- Modifiée
- 08/07/2026
Versions concernées
- 4.0.0 – 5.4.6
- 6.0.0 – 6.1.1
Sources
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Source ajoutée : certfr26/09/2026 09:28 UTC
- Détectée via joomla26/09/2026 09:26 UTC