Description
An improper access check allows unauthorized users to access workflow stage and transition information.
Published: 2026-07-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access check in Joomla! CMS’s com_workflow component enables an attacker to retrieve workflow stage and transition data without proper authorization. The flaw is a classic access‑control weakness (CWE‑284) that exposes the confidentiality of workflow structures and processes.

Affected Systems

The Joomla! CMS product is impacted. No specific patched version is listed, indicating that the issue may exist across multiple releases until an official fix is applied or that the component is disabled.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to the com_workflow endpoint, where the attacker can uncover workflow configuration information but does not gain code execution or broader system compromise.

Generated by OpenCVE AI on July 26, 2026 at 19:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Joomla! CMS security update that addresses the com_workflow access‑control issue
  • Restrict access to the com_workflow component by configuring Joomla!’s ACL to allow only trusted user groups
  • If the workflow component is not required, disable or remove com_workflow to eliminate the attack surface
  • Monitor web server logs for unexpected accesses to workflow URLs and investigate anomalies

Generated by OpenCVE AI on July 26, 2026 at 19:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description An improper access check allows unauthorized users to access workflow stage and transition information.
Title Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-08T09:54:46.961Z

Reserved: 2026-05-26T16:47:13.550Z

Link: CVE-2026-48955

cve-icon Vulnrichment

Updated: 2026-07-07T18:42:07.240Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:15:03Z

Weaknesses