CVE-2026-48902
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- NVD-CWE-noinfo, CWE-319
Description
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Affected packages
| Bitnami | joomla | 3.0.0 → 5.4.6 |
| Bitnami | joomla | 6.0.0 → 6.1.1 |
References
Status: profiled · ingested 2026-07-24T12:00:18.000Z