Executive brief
Joomla! CMS, a popular platform for building websites, contained a flaw where password and username reset emails were sent with insecure links. Even if a website was using secure encryption (HTTPS), the reset links would default to an unencrypted format (HTTP) unless a specific setting was enabled. This could allow an attacker on the same network as the user to intercept the reset link and potentially take over their account.
Technical details
A transport encryption downgrade vulnerability exists in Joomla! CMS versions 3.9.0 through 5.4.5 and 6.0.0 through 6.1.0. The core password and username reset components fail to enforce HTTPS for generated reset links when the global 'Force SSL' configuration is disabled, even if the current request is served over HTTPS. This results in 'Mixed Content' or insecure link generation. An attacker capable of monitoring unencrypted network traffic (e.g., via a man-in-the-middle attack) could intercept these reset tokens. The issue is resolved in versions 5.4.6 and 6.1.1.
Affected products
- Joomla! CMS 3.9.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-04-20: other: Reported date
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: disclosed: NVD publication date