Security
Joomla com_fields access flaw affects 4.x and 6.x
Joomla sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 are affected by an Incorrect Access Control issue in com_fields; administrators should upgrade to 5.4.7 or 6.1.2.
The Joomla project has disclosed an improper access check affecting webservices endpoints in the com_fields component. The flaw could allow unauthorized users to create custom fields.
The advisory assigns the issue a Severity of Moderate and a Probability of Low. Its exploit type is Incorrect Access Control, and it is tracked as CVE-2026-48958.
- Affected Joomla CMS versions:
4.0.0-5.4.6 - Affected Joomla CMS versions:
6.0.0-6.1.1 - Fixed versions:
5.4.7and6.1.2
Administrators should review their installations and upgrade to the applicable fixed version. The issue was reported by Federico Brasili on 2026-05-05, and the Joomla project published the fix on 2026-07-07. The advisory identifies the affected area as webservices endpoints and directs questions to the JSST at the Joomla! Security Centre.
Published by the Joomla Security Centre.