Improper Access Control Flaw in Joomla Scheduler Task Management
CVE-2026-48900

6.4MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-48900?

An improper access control vulnerability in Joomla's scheduler component exposes scheduler tasks to unauthorized manipulation by low-privileged users. This flaw permits such users to alter the task types of existing scheduler tasks, potentially leading to unintended behavior and security concerns within the application. It is crucial for Joomla administrators to apply the recommended security updates promptly to safeguard their installations.

Affected Version(s)

Joomla! CMS 4.1.0-5.4.5

Joomla! CMS 6.0.0-6.1.0

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Federico Brasili, https://www.linkedin.com/in/federico-brasili-00b4b7332/
.