[20260809] - Core - Improper ACL checks when injection schema.org contact data
Joomla fixed CVE-2026-73372, an improper ACL check that leaks inaccessible contact items' data into schema.org snippets, affecting CMS 5.1.0-5.4.7 and 6.0.0-6.1.2.
Joomla security advisory 20260809 describes CVE-2026-73372, an incorrect access control issue when injecting schema.org contact data. Improper access checks inject contact information for inaccessible contact items into schema.org snippets, exposing restricted data. Affected versions are 5.1.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Stefan Wendhausen on 2026-07-31.
- Improper ACL check leaks inaccessible contact data in schema.org snippets
- Affects Joomla CMS 5.1.0-5.4.7 and 6.0.0-6.1.2
- Fixed in Joomla 5.4.8 and 6.1.3
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-73372 | Improper ACL check leaks restricted contact data via schema.org in Joomla! Core Joomla! Core 5.1.0 through 5.4.7 and 6.0.0 through 6.1.2 contain an improper access-control check (CWE-284) in the code that injects schema.org contact data into pages. When such a page is generated, the flawed check pulls in contact information from contact items the viewer is not authorized to see, embedding it in the schema.org snippet served to visitors. An attacker gains disclosure of contact details that should have been restricted; the CVSS 4.0 score of 5.1 (medium) reflects this low-confidentiality, network-exploitable issue with no impact on integrity or availability. Sites running the affected Joomla branches that render schema.org contact data are exposed, while installations on other versions or not using this feature are not. No public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS estimates a 0.2% probability of exploitation within 30 days, so no exploitation is currently known. Do: Update Joomla! Core to a release newer than the affected ranges (later than 5.4.7 on the 5.x branch and later than 6.1.2 on the 6.x branch) per the Joomla security advisory dated 2026-08-09. As an interim mitigation, disable or reconfigure schema.org contact-data output and review whether restricted contact items have been exposed in snippets. No active exploitation is known, but defenders monitoring Joomla estates should prioritize the update since the affected branches are current major versions. | 5.1 | <1% |
| mass≈2-3 million Joomla installations, with only the subset using the contacts component / schema.org output actually leaking data |
Project: Joomla! SubProject: CMS Impact: Low Severity: Low Probability: Low Versions: 5.1.0-5.4.7,6.0.0-6.1.2 Exploit type: Incorrect Access Control Reported Date: 2026-07-31 Fixed Date: 2026-08-18 CVE Number: CVE-2026-73372 Description An improper access check injects contact information for unaccessible contact items into schema.org snippets. Affected Installs Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Stefan Wendhausen
This source does not provide full text. Read it at developer.joomla.org.