CVE-2026-48901 Details
Description
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
A vulnerability exists in Joomla! CMS versions 4.0.0 prior to 5.4.5 and 6.0.0 prior to 6.1.0, where the InputFilter::getInstance() method failed to include a security-sensitive parameter in the instance cache key. This oversight could lead to improper caching behavior, potentially allowing for security-sensitive data to be cached incorrectly or not at all.
Users are advised to upgrade to Joomla! CMS versions 5.4.6 or 6.1.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://developer.joomla.org/security-centre/1049-20260517-core-incorrect-cache-key-construction-for-inputfilter-objects.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-524 | Use of Cache Containing Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| joomla joomla! | >= 4.0.0, < 5.4.6 >= 6.0.0, < 6.1.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |