Privilege Escalation Vulnerability in Joomla's User Management Component
CVE-2026-48898
8.2HIGH
What is CVE-2026-48898?
This vulnerability within Joomla's user management component is caused by an improper access control mechanism that permits unauthorized privilege escalation during the com_users batch task execution. As a result, attackers may gain elevated permissions, potentially leading to unauthorized actions or data exposure. Website administrators are strongly advised to apply the latest security patches to mitigate the risk associated with this vulnerability.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.5
Joomla! CMS 6.0.0-6.1.0
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Christos Papakonstantinou, Cantina
Adrian Junge, vulno