Security
Joomla workflow access checks fixed in security update
Administrators running Joomla! CMS 5.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix an incorrect access control vulnerability affecting workflow stage changes.
The Joomla project says the flaw could let unauthorized users update the workflow stage of content they cannot access. The issue affects the Joomla! CMS and concerns how access permissions are checked during workflow stage changes.
The project rates the impact as Low, the severity as Moderate, and the probability as Moderate. The exploit type is Incorrect Access Control, and the issue is tracked as CVE-2026-92223.
- Affected
Joomla! CMSversions:5.0.0-5.4.8and6.0.0-6.1.3 - Fixed versions:
5.4.9and6.1.4 - Reported date: 2026-08-27
- Fixed date: 2026-09-25
Site owners should plan the appropriate update for their current major version and review workflow-related permissions after upgrading. Developers and administrators who maintain custom workflow integrations should also verify that access checks behave as expected.
Published by the Joomla Security Centre.