CVE-2026-48899: Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
Published May 26, 2026
·Updated
An improper access check allows privilege escalation through the comusers batch task.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=4.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48899?
CVE-2026-48899 has a medium severity rating of 5.3.
2
How do I fix CVE-2026-48899?
To fix CVE-2026-48899, ensure that you update Joomla to the latest version that addresses this improper access control issue.
3
What type of vulnerability is represented by CVE-2026-48899?
CVE-2026-48899 is classified as an improper access control vulnerability.
4
What can be exploited through CVE-2026-48899?
CVE-2026-48899 allows for privilege escalation through the com_users batch task.
5
Which software is affected by CVE-2026-48899?
CVE-2026-48899 affects Joomla! Core, specifically its sample data plugins.