CVE-2026-48898
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-284, NVD-CWE-noinfo
Description
An improper access check allows privilege escalation through the com_users batch task.
Affected packages
| Bitnami | joomla | 4.0.0 → 5.4.6 |
| Bitnami | joomla | 6.0.0 → 6.1.1 |
References
Status: profiled · ingested 2026-07-24T12:00:18.000Z