CVE-2026-48956Disclosure(joomla / joomla\!)

LOWCVSS 5.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch joomla joomla\! systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper access check allows users to display a list of modules in the frontend.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joomla\!

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-07); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
joomla\!

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-07: 3Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-07: 3Technical Details · 2026-07-08: 107-0707-08
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-073
Disclosure2General1
2026-07-081
Disclosure1
Full discourse4 posts
  • sin99xx@sin99xx
    Disclosure

    Another one from the frontend: CVE-2026-48956 in Joomla! CMS Improper access control in com_modules lets users list modules they shouldn't see. Affected: 4.0.0-5.4.6, 6.0.0-6.1.1 Fixed in 5.4.7 & 6.1.2 Reported it a while back, finally public. Stay patched folks. https://t.co/E0QgR9dUoq

    Post summary

    The tweet announces the disclosure of CVE‑2026‑48956 in Joomla! CMS, describing an access control flaw, affected versions, and the availability of a patch.

    5212672.2K
    937 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Joomla! CMS için yeni güvenlik zafiyeti "CVE-2026-48956" – com_modules bileşeninde bulunan Incorrect Access Control zafiyeti, frontend tarafında kullanıcıların yetkileri dışında kalan modüllerin listesini görüntüleyebilmesine neden oluyor. 📌 Etkilenen sürümler • 4.0.0 – 5.4.6 • 6.0.0 – 6.1.1 ✅ Düzeltilen sürümler • 5.4.7 • 6.1.2 Bu açık doğrudan RCE veya yetki yükseltme sağlamasa da, modül isimleri ve site yapısı hakkında bilgi sızdırarak saldırganların keşif (reconnaissance) sürecini kolaylaştırabilir. Etkilenen Joomla kurulumlarının en kısa sürede güncellenmesi önerilir.

    Post summary

    The text announces Joomla! CMS CVE‑2026‑48956, detailing an incorrect access‑control flaw that reveals module names and urges users to apply the latest patches.

    00010178
    1.2K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-48956 An improper access check allows users to display a list of modules in the frontend. https://www.cve.org/CVERecord?id=CVE-2026-48956

    Post summary

    The post simply reports CVE‑2026‑48956, noting an improper access check that lets users see module listings in the frontend, without any further details on exploitation or remediation.

    00010674
    57.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48956 An improper access check allows users to display a list of modules in the frontend. https://www.cve.org/CVERecord?id=CVE-2026-48956 ----- Traducción: CVE-2026-48956 Un fallo de control de acceso inapropiado permite a los usuarios mostrar una lista de mó… http://infoflow.cloud`

    Post summary

    The post introduces CVE-2026-48956, describing an improper access check that lets users view a module list on the frontend, and cites the official CVE record but provides no PoC, exploit code, or patch information.

    0000035
    91 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlajoomla\!---

Explore more