Executive brief
A security vulnerability in the Joomla! content management system could allow an unauthorized user to gain elevated permissions. This occurs due to a flaw in how the system handles user management tasks, potentially allowing an attacker to take control of administrative functions. Organizations using affected versions of Joomla! should update immediately to prevent unauthorized access to their website's backend.
Technical details
A privilege escalation vulnerability exists in Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The flaw is located within the 'com_users' component's batch task processing logic, where improper access control checks (CWE-284) fail to sufficiently validate user permissions. An attacker can exploit this via the network to escalate their privileges within the application. The vulnerability has been addressed in Joomla! versions 5.4.6 and 6.1.1.
Affected products
- Joomla! CMS 4.0.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-04-15: other: Reported
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: disclosed: Public advisory published