Privilege Escalation Vulnerability in Joomla's User Management Component
CVE-2026-48898

8.2HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-48898?

This vulnerability within Joomla's user management component is caused by an improper access control mechanism that permits unauthorized privilege escalation during the com_users batch task execution. As a result, attackers may gain elevated permissions, potentially leading to unauthorized actions or data exposure. Website administrators are strongly advised to apply the latest security patches to mitigate the risk associated with this vulnerability.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.5

Joomla! CMS 6.0.0-6.1.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christos Papakonstantinou, Cantina
Adrian Junge, vulno
.