Description
An improper access check allows unauthorized users to access com_privacy datasets.
Published: 2026-07-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access check in the Joomla! CMS com_privacy component allows attackers to retrieve user privacy information via webservice endpoints without authentication. This violates proper access control (CWE‑284) and exposes sensitive data to unauthorized parties.

Affected Systems

The affected product is Joomla! CMS from the Joomla! Project. No explicit version numbers are listed, so any installation that includes the com_privacy component is potentially vulnerable until the vendor releases a fix. The issue exists in the core component. Administrators should verify if the com_privacy module is deployed and whether the CMS version is below the latest security release.

Risk and Exploitability

The CVSS score of 6.4 classifies the flaw as medium severity. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not currently referenced in the CISA KEV catalog. Attackers could exploit this weakness by sending unauthenticated HTTP requests to the affected webservice endpoints, thereby pulling privacy datasets.

Generated by OpenCVE AI on July 26, 2026 at 19:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Joomla! CMS patch that resolves the com_privacy access control flaw as soon as it becomes available.
  • Restrict external access to the com_privacy webservice endpoints, e.g., by limiting network reachability or enforcing authentication before allowing traffic.
  • Perform vulnerability scanning or penetration testing against the com_privacy component to confirm that the access control issue has been remedied.

Generated by OpenCVE AI on July 26, 2026 at 19:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description An improper access check allows unauthorized users to access com_privacy datasets.
Title Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-08T09:53:48.446Z

Reserved: 2026-05-26T16:47:13.550Z

Link: CVE-2026-48957

cve-icon Vulnrichment

Updated: 2026-07-07T18:40:25.897Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses