CVE-2026-48900
Analyzed Analyzed - Analysis Complete
Improper Access Control in Joomla Scheduler Tasks

Publication date: 2026-05-26

Last updated on: 2026-05-26

Assigner: Joomla! Project

Description
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-26
Last Modified
2026-05-26
Generated
2026-06-16
AI Q&A
2026-05-26
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
joomla joomla! From 6.0.0 (inc) to 6.1.1 (exc)
joomla joomla! From 4.1.0 (inc) to 5.4.6 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-48900 is a security vulnerability in the Joomla! CMS affecting versions 4.1.0 through 5.4.5 and 6.0.0 through 6.1.0.

The issue involves an improper access check in the com_scheduler component, which allows low-privileged users to edit the task types of existing scheduler tasks.

This means that users who should not have permission to modify certain scheduled tasks can do so due to incorrect access control.

Impact Analysis

This vulnerability could allow unauthorized users with low privileges to modify scheduled tasks within the Joomla! CMS.

Such unauthorized modifications could lead to unexpected or malicious task executions, potentially disrupting normal operations or compromising system integrity.

Although classified as moderate impact with low severity and low probability of exploitation, it still poses a risk to the security and stability of affected Joomla! installations.

Mitigation Strategies

To mitigate this vulnerability, users should upgrade their Joomla! CMS installations to versions 5.4.6 or 6.1.1, where the issue has been fixed.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48900. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart