CVE-2026-48900: Joomla! Core - [20260516] - Incorrect Access Control in com_scheduler
Published May 26, 2026
·Updated
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
Affected Software
3 affected components
Joomla Joomla Core (com_scheduler)
Joomla Joomla\!>=4.1.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48900?
The severity of CVE-2026-48900 is medium, with a CVSS score of 6.4.
2
How do I fix CVE-2026-48900?
To fix CVE-2026-48900, update Joomla to the latest version that addresses this improper access control issue.
3
What type of vulnerability is CVE-2026-48900?
CVE-2026-48900 is classified as an improper access control vulnerability in Joomla's com_scheduler component.
4
Who is affected by CVE-2026-48900?
Low privileged users of Joomla can be affected by CVE-2026-48900 as it allows them to edit scheduler task types.
5
When was CVE-2026-48900 published?
CVE-2026-48900 was published on May 26, 2026.