Description
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Published: 2026-07-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access check in the com_contact component of Joomla! CMS allows an attacker to download vCard (vcf) files for contacts that should not be visible to them. This Improper Privilege Management can expose personal data such as phone numbers or email privacy and potentially enabling further social engineering. The vulnerability is a CWE‑284 (Improper Privilege Management) weakness.

Affected Systems

All installations of Joomla! CMS that rules; therefore, all Joomla! sites running this component in its default configuration are at risk. No specific affected version information is provided.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, and the EPSS score is less than 1 %, meaning the probability of publicly available exploitation is low but not zero. It is not listed in the CISA KEV catalog. It can be abused remotely via an HTTP request to the vcf download URL, and requires no authentication. Attackers only need to know a valid contact identifier or guess a working URL pattern. The likely attack vector is sending an unauthenticated HTTP GET request to the com_contact vcf download endpoint.

Generated by OpenCVE AI on July 26, 2026 at 19:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch that fixes the CWE‑284 Improper Privilege Management vulnerability in the com_contact component.
  • Check the official Joomla! Project security advisory for an update that addresses the access control issue in com_contact vcf download.
  • If a patch is not yet available, restrict access to the vcard download endpoint by requiring authentication or by applying a WAF rule to block unauthenticated requests.
  • Review site configuration to ensure the component’s privacy settings are correctly enforced and disable public vCard exports if not required.

Generated by OpenCVE AI on July 26, 2026 at 19:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
Title Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-08T09:52:52.045Z

Reserved: 2026-05-26T16:47:13.550Z

Link: CVE-2026-48948

cve-icon Vulnrichment

Updated: 2026-07-07T18:46:37.336Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses