CVE-2026-48902: Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links
Published May 26, 2026
·Updated
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48902?
CVE-2026-48902 has a critical severity rating of 9.8 based on CVSS 3.1.
2
What vulnerabilities does CVE-2026-48902 exploit?
CVE-2026-48902 exploits the failure to enforce SSL, allowing for transport encryption downgrade in password and username reset links.
3
How do I fix CVE-2026-48902?
To fix CVE-2026-48902, ensure the 'Force SSL' flag is set to enforce HTTPS connections for password and username reset links.
4
Who is affected by CVE-2026-48902?
All Joomla core users who do not have the 'Force SSL' flag enabled are affected by CVE-2026-48902.
5
When was CVE-2026-48902 published?
CVE-2026-48902 was published on May 26, 2026.