CVE-2026-35220: Joomla! Core - [20260505] - CSRF in user activation endpoint
Published May 26, 2026
·Updated
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of comusers.
Affected Software
2 affected components
Joomla Joomla! Core
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35220?
CVE-2026-35220 has a medium severity rating of 4.6.
2
How do I fix CVE-2026-35220?
To fix CVE-2026-35220, ensure that CSRF token validation is implemented in the admin activation endpoint of com_users.
3
What type of vulnerability is CVE-2026-35220?
CVE-2026-35220 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which software is affected by CVE-2026-35220?
CVE-2026-35220 affects the Joomla! Core software, specifically the com_users component.
5
When was CVE-2026-35220 published?
CVE-2026-35220 was published on May 26, 2026.