CVE-2026-48955: Joomla! Core - [20260709] - Incorrect Access Control in com_workflow
Published Jul 7, 2026
·Updated
An improper access check allows unauthorized users to access workflow stage and transition information.
Affected Software
2 affected components
Joomla! Joomla! Core
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48955?
CVE-2026-48955 has a risk rating of 30, indicating a high severity vulnerability.
2
How do I fix CVE-2026-48955?
To fix CVE-2026-48955, you need to update your Joomla! Core to the latest version that addresses the access control issue.
3
What impacts does CVE-2026-48955 have on Joomla! security?
CVE-2026-48955 allows unauthorized users to access sensitive workflow stage and transition information, posing a significant security risk.
4
Is there a workaround for CVE-2026-48955?
No official workaround is provided for CVE-2026-48955; applying the security patch is the recommended solution.
5
When was CVE-2026-48955 published?
CVE-2026-48955 was published on July 7, 2026.