Security
Joomla fixes reset-link encryption downgrade
Administrators running Joomla! CMS 3.9.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6,6.1.1 to fix a Low-severity transport encryption downgrade affecting password and username reset links, tracked as CVE-2026-48902.
The issue affected the password and username reset features when a site used an HTTPS connection but the Force SSL flag had not been explicitly enabled. In that configuration, Joomla could generate reset links using plain HTTP rather than HTTPS.
The Joomla project classifies the exploit type as Mixed Content. It assigns the issue an impact of Low, severity of Low and probability of Low. Although the advisory does not describe active exploitation, administrators should apply the available maintenance release rather than rely on configuration changes alone.
- Affected releases:
3.9.0-5.4.5,6.0.0-6.1.0 - Upgrade target:
5.4.6,6.1.1 - CVE:
CVE-2026-48902 - Reported date: 2026-04-20
- Fixed date: 2026-05-26
The issue was reported by ZeroXJacks via Github. Site teams should test the upgrade in their normal deployment process and confirm that reset messages now contain appropriately protected links.
Published by the Joomla Security Centre.