Privilege Escalation Vulnerability in Joomla! Webservice Endpoint
CVE-2026-48904
8.2HIGH
What is CVE-2026-48904?
An improper access check within the com_users group editing webservice endpoint of Joomla! may allow unauthorized users to escalate their privileges. This vulnerability exposes sensitive webservice functionalities, which can lead to unauthorized actions being performed by users who should have restricted access rights. Organizations utilizing affected Joomla! versions are advised to apply security patches to remediate this potential risk.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.5
Joomla! CMS 6.0.0-6.1.0