Junglewise Threat Intelligence

CVE-2026-48899: Joomla! CMS privilege escalation in com_users batch task

CVE-2026-48899 · Severity: info · CVSS 5.3 · Published 2026-05-26

Technologies: Joomla CMS. Vendors: Joomla.

Executive brief

Joomla!, a popular website management system, contains a security flaw in how it handles user permissions for certain administrative tasks. An attacker with basic user access could exploit this to gain higher-level privileges or perform unauthorized actions related to sample data installation. This could lead to unauthorized changes to the website or a compromise of administrative controls.

Technical details

An improper access control vulnerability (CWE-284) exists in Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The flaw is located within the com_users batch task and sample data plugins, where insufficient validation of user permissions allows unauthorized users to perform actions they should not have access to. An attacker with low-privileged credentials can exploit this over the network to escalate their privileges or manipulate sample data installation. The issue is resolved in Joomla! versions 5.4.6 and 6.1.1.

Affected products

  • Joomla! CMS 4.0.0-5.4.5, 6.0.0-6.1.0

Timeline

  • 2026-04-23: disclosed: Reported to Joomla! Security Centre
  • 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
  • 2026-05-26: advisory

References