CVE-2026-48947: Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints
Published Jul 7, 2026
·Updated
An improper access check allows privileged users to overwrite media files without editing permissions.
Affected Software
3 affected components
Joomla! Joomla! Core=[20260701]
Joomla Joomla\!>=4.1.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48947?
CVE-2026-48947 has a risk rating of 37.
2
How do I fix CVE-2026-48947?
To fix CVE-2026-48947, update to the latest version of the Joomla! Core that addresses the access control issue.
3
What does CVE-2026-48947 affect?
CVE-2026-48947 affects the com_media webservice endpoints in Joomla!.
4
What is the nature of the vulnerability in CVE-2026-48947?
CVE-2026-48947 involves incorrect access control that allows privileged users to overwrite media files.
5
Who is impacted by CVE-2026-48947?
Privileged users in Joomla! with access to the affected endpoints may be impacted by CVE-2026-48947.