Description
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Published: 2026-07-07
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla! CMS vulnerability allows attackers to create custom fields through the com_fields webservice endpoints without the appropriate access controls. This flaw, identified as CWE‑284, permits an attacker to modify the site’s data layouts by adding new fields can grant the attacker elevated capabilities within the CMS, potentially affecting the integrity and availability of site data.

Affected Systems

This vulnerability affects Joomla! CMS installations that expose the com_fields webservice endpoints; no version exclusions are listed, meaning any Joomla! release lacking the patch is vulnerable.

Risk and Exploitability

The CVSS score of 6.4 denotes moderate severity. The EPSS score of <1% suggests a low probability of exploitation. Based on the description, it is inferred that the webservice endpoints do not perform additional authentication or role verification, allowing an attacker to create fields via standard HTTP requests. The vulnerability is not listed in the CISA KEV catalog, indicating that no widespread exploitation has been documented yet, but awareness and monitoring are prudent.

Generated by OpenCVE AI on July 26, 2026 at 19:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Joomla! CMS update that contains the com_fields access control fix.
  • If the com, disable or restrict its endpoints to prevent unauthorized use.
  • Configure role‑based access control on all API endpoints so that only authorized users can create or modify custom fields.

Generated by OpenCVE AI on July 26, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Joomla
Joomla joomla!
Vendors & Products Joomla
Joomla joomla!

Tue, 07 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Title Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-08T09:55:50.241Z

Reserved: 2026-05-26T16:47:13.550Z

Link: CVE-2026-48958

cve-icon Vulnrichment

Updated: 2026-07-07T18:39:16.329Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:15:03Z

Weaknesses