Impact
An improper access check in the Joomla! CMS com_privacy component allows attackers to retrieve user privacy information via webservice endpoints without authentication. This violates proper access control (CWE‑284) and exposes sensitive data to unauthorized parties.
Affected Systems
The affected product is Joomla! CMS from the Joomla! Project. No explicit version numbers are listed, so any installation that includes the com_privacy component is potentially vulnerable until the vendor releases a fix. The issue exists in the core component. Administrators should verify if the com_privacy module is deployed and whether the CMS version is below the latest security release.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as medium severity. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not currently referenced in the CISA KEV catalog. Attackers could exploit this weakness by sending unauthenticated HTTP requests to the affected webservice endpoints, thereby pulling privacy datasets.
OpenCVE Enrichment