Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes scheduler access control flaw

Administrators running affected Joomla versions should upgrade to 5.4.6 or 6.1.1 to address an incorrect access control issue in com_scheduler.

The Joomla project has published a security advisory for an improper access check in the CMS scheduler component. The issue could allow low privileged users to edit the task types belonging to existing scheduler tasks.

The advisory identifies the issue as CVE-2026-48900. It classifies the impact as Moderate, the severity as Low, and the probability as Low. The exploit type is Incorrect Access Control.

  • Affected versions: 4.1.0-5.4.5 and 6.0.0-6.1.0
  • Fixed versions: 5.4.6 and 6.1.1
  • Component: com_scheduler

The issue was reported on 2026-04-29, and the Joomla project published the fix on 2026-05-26. Site administrators should review their installed CMS branch and apply the corresponding update. The advisory credits Federico Brasili with reporting the vulnerability.

Published by the Joomla Security Centre.