Privilege Escalation Vulnerability in Joomla! Webservice Endpoint
CVE-2026-48904

8.2HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-48904?

An improper access check within the com_users group editing webservice endpoint of Joomla! may allow unauthorized users to escalate their privileges. This vulnerability exposes sensitive webservice functionalities, which can lead to unauthorized actions being performed by users who should have restricted access rights. Organizations utilizing affected Joomla! versions are advised to apply security patches to remediate this potential risk.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.5

Joomla! CMS 6.0.0-6.1.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christos Papakonstantinou, Cantina
.