Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla 6.0.0-6.1.0 affected by CSRF activation flaw

Administrators running Joomla! CMS 6.0.0-6.1.0 should upgrade to 6.1.1 to address a Moderate CSRF vulnerability in the user activation endpoint.

The Joomla project says the issue affects the administrative activation endpoint in com_users. The endpoint did not validate a CSRF token, creating a cross-site request forgery attack vector that could allow an unwanted activation request to be submitted by a victim's browser.

The advisory classifies the exploit type as CSRF. Its impact, severity and probability ratings are each Moderate. The vulnerability is tracked as CVE-2026-35220.

Sun HuangnSec reported the issue on 2026-03-28. The Joomla project published the fix on 2026-05-26, with 6.1.1 identified as the solution. Site owners should review their installed CMS version and plan the update promptly, particularly where administrator accounts and user-management functions are exposed to untrusted browsing sessions.

Published by the Joomla Security Centre.