Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla sample data plugins expose access-control flaw

The Joomla project says Joomla! CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by an access-control flaw in sample data plugins. Administrators should upgrade to 5.4.6 or 6.1.1, as appropriate.

The vulnerability allows unauthorized users to carry out actions associated with installing sampledata. It affects the Joomla! CMS and is classified by the project as an Incorrect Access Control issue.

The advisory assigns the issue an Impact of High, a Severity of Moderate and a Probability of Moderate. Its CVE identifier is CVE-2026-48899. Site administrators should treat the upgrade as the appropriate remediation for installations using the affected releases.

  • Reported date: 2026-04-23
  • Fixed date: 2026-05-26
  • Reported by: 廖双, JSST

The Joomla Security Strike Team published the notice on 2026-05-26. It identifies the affected functionality as sample data plugins and directs users to the fixed releases listed in the advisory. The project’s contact point for questions is the JSST at the Joomla! Security Centre.

Published by the Joomla Security Centre.