Executive brief
Joomla!, a popular website management system, contains a security flaw in how it handles user permissions for certain administrative tasks. An attacker with basic user access could exploit this to gain higher-level privileges or perform unauthorized actions related to sample data installation. This could lead to unauthorized changes to the website or a compromise of administrative controls.
Technical details
An improper access control vulnerability (CWE-284) exists in Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The flaw is located within the com_users batch task and sample data plugins, where insufficient validation of user permissions allows unauthorized users to perform actions they should not have access to. An attacker with low-privileged credentials can exploit this over the network to escalate their privileges or manipulate sample data installation. The issue is resolved in Joomla! versions 5.4.6 and 6.1.1.
Affected products
- Joomla! CMS 4.0.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-04-23: disclosed: Reported to Joomla! Security Centre
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: advisory