Security
Joomla 6.0.0-6.1.0 affected by CSRF activation flaw
Administrators running Joomla! CMS 6.0.0-6.1.0 should upgrade to 6.1.1 to address a Moderate CSRF vulnerability in the user activation endpoint.
The Joomla project says the issue affects the administrative activation endpoint in com_users. The endpoint did not validate a CSRF token, creating a cross-site request forgery attack vector that could allow an unwanted activation request to be submitted by a victim's browser.
The advisory classifies the exploit type as CSRF. Its impact, severity and probability ratings are each Moderate. The vulnerability is tracked as CVE-2026-35220.
Sun HuangnSec reported the issue on 2026-03-28. The Joomla project published the fix on 2026-05-26, with 6.1.1 identified as the solution. Site owners should review their installed CMS version and plan the update promptly, particularly where administrator accounts and user-management functions are exposed to untrusted browsing sessions.
Published by the Joomla Security Centre.