Improper Access Control Flaw in Joomla Scheduler Task Management
CVE-2026-48900
6.4MEDIUM
What is CVE-2026-48900?
An improper access control vulnerability in Joomla's scheduler component exposes scheduler tasks to unauthorized manipulation by low-privileged users. This flaw permits such users to alter the task types of existing scheduler tasks, potentially leading to unintended behavior and security concerns within the application. It is crucial for Joomla administrators to apply the recommended security updates promptly to safeguard their installations.
Affected Version(s)
Joomla! CMS 4.1.0-5.4.5
Joomla! CMS 6.0.0-6.1.0
References
CVSS V4
Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Federico Brasili, https://www.linkedin.com/in/federico-brasili-00b4b7332/