Joomla core: incorrect access control

CVE-2026-48956

Public research by Warisjeet Singh sin99xx

Disclosed

The public finding

What was found.

An improper access check allowed users to display a list of modules in the frontend.

Sources and evidence.

read the advisory ↗
The evidence: the Joomla advisory, verbatim
developer.joomla.org · CVE-2026-48956 published 2026
"An improper access check allows users to display a list
of modules in the frontend."