Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla com_media access flaw fixed in 5.4.7 and 6.1.2

Joomla! CMS installations running 4.1.0-5.4.6 or 6.0.0-6.1.1 are affected by incorrect access control in com_media webservice endpoints; administrators should upgrade to 5.4.7 or 6.1.2, as appropriate.

The Joomla project has addressed a permission-checking weakness that could let privileged users overwrite media files even when they do not have editing permissions. The issue is tracked as CVE-2026-48947 and affects the Joomla! CMS.

The vulnerable version ranges are 4.1.0-5.4.6 and 6.0.0-6.1.1. The corrected releases are 5.4.7 and 6.1.2, respectively. Administrators should identify which supported branch their site uses and apply the matching update.

The advisory classifies the exploit type as Incorrect Access Control. Its assigned impact is Moderate, while the severity is Low and the probability is Low. The affected area is the com_media webservice endpoints, so sites that allow privileged backend access should prioritise checking their installed version.

The issue was reported by Federico Brasili. The Joomla project lists the reported date as 2026-05-05 and the fixed date as 2026-07-07.

Published by the Joomla Security Centre.