ZeroHour
Joomla Security Centrepublished ()ingested [email protected] (Joomla! Security Strike Team)

[20260809] - Core - Improper ACL checks when injection schema.org contact data

lowAdvisoryimportance 24CVE-2026-73372
AI summary · glm-5.3-flash

Joomla fixed CVE-2026-73372, an improper ACL check that leaks inaccessible contact items' data into schema.org snippets, affecting CMS 5.1.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260809 describes CVE-2026-73372, an incorrect access control issue when injecting schema.org contact data. Improper access checks inject contact information for inaccessible contact items into schema.org snippets, exposing restricted data. Affected versions are 5.1.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Stefan Wendhausen on 2026-07-31.

  • Improper ACL check leaks inaccessible contact data in schema.org snippets
  • Affects Joomla CMS 5.1.0-5.4.7 and 6.0.0-6.1.2
  • Fixed in Joomla 5.4.8 and 6.1.3
VendorsJoomla
ProductsJoomla CMS
OrganizationsJoomla

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73372
Improper ACL check leaks restricted contact data via schema.org in Joomla! Core

Joomla! Core 5.1.0 through 5.4.7 and 6.0.0 through 6.1.2 contain an improper access-control check (CWE-284) in the code that injects schema.org contact data into pages. When such a page is generated, the flawed check pulls in contact information from contact items the viewer is not authorized to see, embedding it in the schema.org snippet served to visitors. An attacker gains disclosure of contact details that should have been restricted; the CVSS 4.0 score of 5.1 (medium) reflects this low-confidentiality, network-exploitable issue with no impact on integrity or availability. Sites running the affected Joomla branches that render schema.org contact data are exposed, while installations on other versions or not using this feature are not. No public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS estimates a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.

Do: Update Joomla! Core to a release newer than the affected ranges (later than 5.4.7 on the 5.x branch and later than 6.1.2 on the 6.x branch) per the Joomla security advisory dated 2026-08-09. As an interim mitigation, disable or reconfigure schema.org contact-data output and review whether restricted contact items have been exposed in snippets. No active exploitation is known, but defenders monitoring Joomla estates should prioritize the update since the affected branches are current major versions.

5.1<1%
  • Joomla! Core 5.1.0 - 5.4.7
  • Joomla! Core 6.0.0 - 6.1.2
mass≈2-3 million Joomla installations, with only the subset using the contacts component / schema.org output actually leaking data
Full article

Project: Joomla! SubProject: CMS Impact: Low Severity: Low Probability: Low Versions: 5.1.0-5.4.7,6.0.0-6.1.2 Exploit type: Incorrect Access Control Reported Date: 2026-07-31 Fixed Date: 2026-08-18 CVE Number: CVE-2026-73372 Description An improper access check injects contact information for unaccessible contact items into schema.org snippets. Affected Installs Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Stefan Wendhausen

This source does not provide full text. Read it at developer.joomla.org.