CVE-2026-48898: Joomla! Core - [20260513] - Privilege escalation through com_users batch task
Published May 26, 2026
·Updated
An improper access check allows privilege escalation through the comusers batch task.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=4.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48898?
CVE-2026-48898 has a high severity rating of 8.2.
2
How do I fix CVE-2026-48898?
To fix CVE-2026-48898, ensure that your Joomla software is updated to the latest version released after May 2026.
3
What is CVE-2026-48898 about?
CVE-2026-48898 describes a privilege escalation vulnerability in Joomla! that occurs due to improper access checks in the com_users batch task.
4
Who is affected by CVE-2026-48898?
All users and installations of Joomla! that are utilizing the com_users component are potentially affected by CVE-2026-48898.
5
Can CVE-2026-48898 be exploited remotely?
Yes, CVE-2026-48898 can be exploited remotely due to its nature of improper access checks.