CVE-2026-48904: Joomla! Core - [20260514] - Privilege escalation through com_users webservice endpoints
Published May 26, 2026
·Updated
An improper access check allows privelege escalation through the comusers group editing webservice endpoint.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=4.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48904?
CVE-2026-48904 has a severity rating of high, with a CVSS score of 8.2.
2
How do I fix CVE-2026-48904?
To fix CVE-2026-48904, ensure your Joomla installation is updated to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-48904?
CVE-2026-48904 is a privilege escalation vulnerability related to improper access checks.
4
What software is affected by CVE-2026-48904?
CVE-2026-48904 affects Joomla! and its core component, com_users.
5
What can be exploited in CVE-2026-48904?
CVE-2026-48904 allows attackers to escalate privileges through the com_users group editing webservice endpoint.