CVE-2026-48902

Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links

criticalEPSS 0.3%

Affected

  • bitnami/joomla 3.0.0..*
  • bitnami/joomla 6.0.0..*

Description

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamijoomla
3.0.06.0.0

Metrics

9.8
Source: nvd-v3
23.5 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-05-29 08:44 UTC

References & sources