ZeroHour

CVE-2026-73372

mass

Improper ACL check leaks restricted contact data via schema.org in Joomla! Core

CVSS 4.0
5.1 medium
EPSS
<1%p11
Published
()
Modified
AI analysis

Joomla! Core 5.1.0 through 5.4.7 and 6.0.0 through 6.1.2 contain an improper access-control check (CWE-284) in the code that injects schema.org contact data into pages. When such a page is generated, the flawed check pulls in contact information from contact items the viewer is not authorized to see, embedding it in the schema.org snippet served to visitors. An attacker gains disclosure of contact details that should have been restricted; the CVSS 4.0 score of 5.1 (medium) reflects this low-confidentiality, network-exploitable issue with no impact on integrity or availability. Sites running the affected Joomla branches that render schema.org contact data are exposed, while installations on other versions or not using this feature are not. No public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS estimates a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.

What to do: Update Joomla! Core to a release newer than the affected ranges (later than 5.4.7 on the 5.x branch and later than 6.1.2 on the 6.x branch) per the Joomla security advisory dated 2026-08-09. As an interim mitigation, disable or reconfigure schema.org contact-data output and review whether restricted contact items have been exposed in snippets. No active exploitation is known, but defenders monitoring Joomla estates should prioritize the update since the affected branches are current major versions.

Affected
Joomla! Core5.1.0 - 5.4.7
Joomla! Core6.0.0 - 6.1.2
Estimated exposure
mass≈2-3 million Joomla installations, with only the subset using the contacts component / schema.org output actually leaking data — Joomla powers roughly 1-2% of all websites per public web-technology surveys (W3Techs), implying millions of live installs in the affected version ranges, though exposure to this flaw is limited to sites that render schema.org contact data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

[20260809] - Core - Improper ACL checks when injection schema.org contact data

Joomla fixed CVE-2026-73372, an improper ACL check that leaks inaccessible contact items' data into schema.org snippets, affecting CMS 5.1.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260809 describes CVE-2026-73372, an incorrect access control issue when injecting schema.org contact data. Improper access checks inject contact information for inaccessible contact items into schema.org snippets, exposing restricted data. Affected versions are 5.1.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Stefan Wendhausen on 2026-07-31.

Joomla Security Centre · 29d agoAdvisoryCVE-2026-73372