Description
An improper access check allows users to display a list of modules in the frontend.
Published: 2026-07-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect access check within Joomla! CMS’s com_modules component that permits any visitor to view a list of installed modules on the site’s front‑end. This disclosure reveals module configuration details, allowing an attacker to gain insight into the site’s structure and potentially identify other weaknesses. The flaw is categorized as CWE‑284, and it provides informational disclosure rather than direct code execution or privilege escalation.

Affected Systems

The affected product is Joomla! CMS from Joomla! Project. No specific version information is provided, suggesting the issue applies to all pre‑patch releases that include the com_modules component. Any Joomla! installation that has not applied the official fix is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. The EPSS score of <1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, so there are no known widespread attacks. The attack vector is inferred to be the web front‑end, as an unauthenticated request can trigger the disclosure. An attacker with no special privileges could enumerate modules simply by browsing the site, which might aid other attacks.

Generated by OpenCVE AI on July 23, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Joomla! CMS security update that addresses CVE‑2026‑48956.
  • If an immediate patch is not available, modify the com_modules ACL to restrict visibility of module listings to authenticated users or specific user groups.
  • Disable or hide the com_modules component from the public front‑end to prevent accidental exposure.

Generated by OpenCVE AI on July 23, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description An improper access check allows users to display a list of modules in the frontend.
Title Joomla! Core - [20260710] - Incorrect Access Control in com_modules
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-08T09:54:45.131Z

Reserved: 2026-05-26T16:47:13.550Z

Link: CVE-2026-48956

cve-icon Vulnrichment

Updated: 2026-07-07T18:38:56.764Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T13:30:04Z

Weaknesses