CVE-2026-48943

CVE-2026-48943: Joomla Extension - getk2.org - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26

Vendor Getk2.Org
Product K2 extension for Joomla
Weakness CWE-915
Published June 25, 2026
Last update June 28, 2026

CVSS base score

What the vulnerability does

01Description

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of their own row in the `#__k2_users` table — none of which are exposed by the K2 frontend profile-edit form.

Explanation of Vulnerability in Simple Terms

02Summary

Insufficient metadata is available to generate a reliable CVE summary. The CVSS score, vector, and CWE classification are all marked unknown, and the affected version range appears malformed (>= 1.0-2.26 and < 1.0-2.26 is empty). A patched version is not documented. Contact the K2 extension vendor or Joomla security resources for clarification before taking action.

What an attacker can do

03Attacker Capabilities

Unable to determine without CVSS vector and CWE data.

Potential impact on your site

04Site Impact

Unable to assess impact without complete vulnerability classification.

Conditions required to exploit

05Prerequisites

Unable to determine without CVSS vector data.

Key dates

06Disclosure timeline

June 25, 2026 CVE published
June 28, 2026 Record updated