CVE-2026-48899 | Joomla CMS up to 5.4.5/6.1.0 com_users access control
A vulnerability was found in Joomla CMS up to 5.4.5/6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component com_users. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2026-48899. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More