CVE-2026-48958: Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints
Published Jul 7, 2026
·Updated
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Affected Software
3 affected components
Joomla! Joomla! Core
Joomla Joomla\!>=4.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48958?
CVE-2026-48958 has a medium severity rating of 6.4.
2
How does CVE-2026-48958 affect Joomla?
CVE-2026-48958 allows unauthorized users to create custom fields through webservices endpoints due to improper access checks.
3
How do I fix CVE-2026-48958?
To fix CVE-2026-48958, ensure that you apply the latest security patch released by Joomla for the core software.
4
What versions of Joomla are affected by CVE-2026-48958?
CVE-2026-48958 affects Joomla! Joomla! Core versions that are vulnerable to the described access control issue.
5
When was CVE-2026-48958 published?
CVE-2026-48958 was published on July 7, 2026.