Description
An improper access check allows users to display a list of modules in the frontend.
Published: 2026-07-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access check in Joomla! CMS’s com_modules component allows any visitor to view a list of modules displayed on the site’s front‑end. The exposed information can reveal module names, configurations and the overall architecture of the site, providing attackers with useful context for further discovery or targeted attacks. The flaw is classified as CWE‑284 and does not provide direct code execution or privilege escalation, but it does provide actionable information.

Affected Systems

All Joomla! CMS installations that include the com_modules component and have not applied the vendor’s security fix are vulnerable. The vendor list indicates that the Joomla! Project’s Joomla! CMS product is affected. No specific version details are supplied, suggesting that all releases of the component that have not been updated are at risk.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity issue. The EPSS score of less than 1% denotes a very low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is the public web front‑end, as an unauthenticated user can trigger the disclosure simply by requesting the module‑listing page. The information obtained could aid subsequent attacks but does not alone compromise confidentiality, integrity or availability of the system.

Generated by OpenCVE AI on August 12, 2026 at 05:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch provided by the Joomla! Project for the com_modules component.
  • If a patch is not immediately available, restrict access to the module listing page by configuring Joomla!’s access control settings or using an .htaccess rule to deny unauthenticated requests.
  • Monitor Joomla! Project security advisories for updates and apply them promptly.

Generated by OpenCVE AI on August 12, 2026 at 05:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description An improper access check allows users to display a list of modules in the frontend.
Title Joomla! Core - [20260710] - Incorrect Access Control in com_modules
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-08T09:54:45.131Z

Reserved: 2026-05-26T16:47:13.550Z

Link: CVE-2026-48956

cve-icon Vulnrichment

Updated: 2026-07-07T18:38:56.764Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-07T19:16:54.313

Modified: 2026-07-09T16:58:49.893

Link: CVE-2026-48956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T05:15:03Z

Weaknesses