Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes privilege escalation in com_users webservices

Joomla! CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a privilege escalation flaw in com_users webservice endpoints. Administrators should upgrade to 5.4.6 or 6.1.1.

The Joomla project has disclosed a security issue involving the group-editing webservice endpoint in com_users. An inadequate access-control check could allow a user to carry out actions beyond their intended permissions, making this a Privilege Escalation vulnerability.

The advisory identifies the issue as CVE-2026-48904. Joomla classifies its impact as High, its Severity as Moderate and the Probability as Low. The affected releases are:

  • Joomla! CMS 4.0.0-5.4.5
  • Joomla! CMS 6.0.0-6.1.0

The project released fixes in Joomla! CMS 5.4.6 and 6.1.1. Site administrators should apply the version appropriate to their current release branch and ensure that the update completes successfully. The issue was reported by Christos Papakonstantinou of Cantina.

The advisory records 2026-04-15 as the reported date and 2026-05-26 as the fixed date. Joomla administrators who need additional information can contact the Joomla! Security Strike Team through the project’s Security Centre.

Published by the Joomla Security Centre.