CVE-2026-48958

Vulnérabilités

CVE-2026-48958

Incorrect Access Control in com_fields webservice endpoints

MEDIUM Joomla CMS Source officielle

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

Source officielle Description du Joomla Security Centre (Joomla).

— Moyenne
SourceSévérité d'origineCVSS
Joomla Security CentreModerate —
CERT-FR (ANSSI)— —
Produit
Joomla CMS
Corrigée dans
5.4.7, 6.1.2
Publiée
07/07/2026
Modifiée
08/07/2026
  • 4.0.0 – 5.4.6
  • 6.0.0 – 6.1.1
  • Joomla Security Centre Source officielle Avis vu
  • CERT-FR (ANSSI) Avis vu

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Source ajoutée : certfr26/09/2026 09:28 UTC
  2. Détectée via joomla26/09/2026 09:26 UTC