Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla com_fields access flaw affects 4.x and 6.x

Joomla sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 are affected by an Incorrect Access Control issue in com_fields; administrators should upgrade to 5.4.7 or 6.1.2.

The Joomla project has disclosed an improper access check affecting webservices endpoints in the com_fields component. The flaw could allow unauthorized users to create custom fields.

The advisory assigns the issue a Severity of Moderate and a Probability of Low. Its exploit type is Incorrect Access Control, and it is tracked as CVE-2026-48958.

  • Affected Joomla CMS versions: 4.0.0-5.4.6
  • Affected Joomla CMS versions: 6.0.0-6.1.1
  • Fixed versions: 5.4.7 and 6.1.2

Administrators should review their installations and upgrade to the applicable fixed version. The issue was reported by Federico Brasili on 2026-05-05, and the Joomla project published the fix on 2026-07-07. The advisory identifies the affected area as webservices endpoints and directs questions to the JSST at the Joomla! Security Centre.

Published by the Joomla Security Centre.