Junglewise Threat Intelligence

CVE-2026-35220: Joomla! CMS CSRF in user activation endpoint

CVE-2026-35220 · Severity: info · CVSS 4.6 · Published 2026-05-26

Technologies: Joomla CMS. Vendors: Joomla.

Executive brief

Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in its user management component. An attacker could trick a logged-in administrator into performing unintended actions, specifically activating user accounts without their consent. This could allow unauthorized users to gain active status on the site if an administrator visits a malicious link.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Joomla! CMS 'com_users' component due to a lack of proper CSRF token validation in the admin activation endpoint. The vulnerability affects Joomla! versions 6.0.0 through 6.1.0. An attacker can exploit this by inducing a high-privileged user (administrator) to visit a specially crafted URL or web page while authenticated. Successful exploitation allows the attacker to trigger the activation of user accounts. The issue is resolved in Joomla! CMS version 6.1.1.

Affected products

  • Joomla! CMS 6.0.0 - 6.1.0

Timeline

  • 2026-03-28: disclosed: Reported to Joomla! Security Centre
  • 2026-05-26: patched: Fixed in version 6.1.1
  • 2026-05-26: advisory

References