The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | |
| Title | Joomla! Core - [20260518] - Transport encryption downgrade for password and username reset links | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-05-26T16:43:32.835Z
Reserved: 2026-05-26T10:06:17.656Z
Link: CVE-2026-48902
No data.
Status : Received
Published: 2026-05-26T17:16:54.970
Modified: 2026-05-26T17:16:54.970
Link: CVE-2026-48902
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.