What the vulnerability does
01Description
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of their own row in the `#__k2_users` table — none of which are exposed by the K2 frontend profile-edit form.
Explanation of Vulnerability in Simple Terms
02Summary
Insufficient metadata is available to generate a reliable CVE summary. The CVSS score, vector, and CWE classification are all marked unknown, and the affected version range appears malformed (>= 1.0-2.26 and < 1.0-2.26 is empty). A patched version is not documented. Contact the K2 extension vendor or Joomla security resources for clarification before taking action.
What an attacker can do
03Attacker Capabilities
Unable to determine without CVSS vector and CWE data.
Potential impact on your site
04Site Impact
Unable to assess impact without complete vulnerability classification.
Conditions required to exploit
05Prerequisites
Unable to determine without CVSS vector data.
Key dates
06Disclosure timeline
June 25, 2026
CVE published
June 28, 2026
Record updated