Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes high-severity com_users privilege escalation

Joomla installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a High-severity privilege escalation issue in com_users; administrators should upgrade to 5.4.6 or 6.1.1.

The Joomla project has disclosed CVE-2026-48898, which concerns an access-control failure in the batch task provided by com_users. Under the advisory's classification, the exploit type is Privilege Escalation. The listed impact is High, while the probability is Low.

Administrators should check their installations against the affected release lines and apply the corresponding maintenance release:

  • 4.0.0-5.4.5 is affected and should be updated to 5.4.6.
  • 6.0.0-6.1.0 is affected and should be updated to 6.1.1.

The issue was reported on 2026-04-15 and fixed on 2026-05-26. The Joomla Security Strike Team credits Adrian Junge aka vulno, Christos Papakonstantinou and Cantina with reporting it. Sites that cannot be updated immediately should review access to administrative functionality involving user-management batch operations and prioritise the upgrade as soon as possible.

Published by the Joomla Security Centre.