Back

CRITICAL

Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links

Published May 26, 2026

Description

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Joomla
Published May 26, 2026
Updated Jun 5, 2026
Reserved May 26, 2026
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Modified
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a