CVE-2026-48902

Vulnérabilités

CVE-2026-48902

Transport encryption downgrade for password and username reset links

LOW Joomla CMS Source officielle

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Source officielle Description du Joomla Security Centre (Joomla).

— Faible
SourceSévérité d'origineCVSS
Joomla Security CentreLow —
CERT-FR (ANSSI)— —
Produit
Joomla CMS
Corrigée dans
5.4.6, 6.1.1
Publiée
26/05/2026
Modifiée
28/05/2026
  • 3.9.0 – 5.4.5
  • 6.0.0 – 6.1.0
  • Joomla Security Centre Source officielle Avis vu
  • CERT-FR (ANSSI) Avis vu

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Source ajoutée : certfr26/09/2026 09:28 UTC
  2. Détectée via joomla26/09/2026 09:26 UTC