Joomla core: incorrect access control
CVE-2026-48956
Public research by Warisjeet Singh sin99xx
Disclosed
The public finding
What was found.
An improper access check allowed users to display a list of modules in the frontend.
Sources and evidence.
The evidence: the Joomla advisory, verbatim
developer.joomla.org · CVE-2026-48956
published 2026
"An improper access check allows users to display a list of modules in the frontend."