Improper Access Control in Joomla Core by Joomla
CVE-2026-73372

5.1MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
18 August 2026

What is CVE-2026-73372?

The Joomla! Core contains a vulnerability where improper access control allows unpermitted access to contact data for inaccessible items. This flaw presents a risk as it can lead to sensitive information being unintentionally displayed in schema.org snippets, potentially exposing confidential contact information that should remain protected.

Affected Version(s)

Joomla! CMS 5.1.0-5.4.6

Joomla! CMS 6.0.0-6.1.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Wendhausen
.