Executive brief
Joomla!, a popular content management system used to build websites, contains a security flaw in its user management web service. This vulnerability allows an attacker to gain unauthorized higher-level permissions, potentially leading to full control over the website's user groups. Organizations should update their Joomla! installations immediately to prevent unauthorized administrative access.
Technical details
A privilege escalation vulnerability exists in Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The flaw is rooted in an improper access control (CWE-284) within the 'com_users' component's webservice endpoint responsible for group editing. A remote attacker can exploit this lack of sufficient validation to modify user group assignments or permissions without appropriate authorization. The attack is network-reachable and requires no user interaction, though it may depend on specific environmental conditions (AT:P). The issue is resolved in Joomla! versions 5.4.6 and 6.1.1.
Affected products
- Joomla! CMS 4.0.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-04-15: other: Reported to vendor
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: disclosed: Public advisory published