How to Create a New Joomla Super User When You Cannot Log In

If every usable Super User account is unavailable, the goal is to regain controlled Administrator access and create a normal replacement account—not to leave a public emergency credential in the database. On Joomla 6, avoid historical SQL examples that depend on obsolete password hashes.

Back up the site first

Create a current files-and-database backup and confirm you are working on the correct Joomla installation. Emergency Super User recovery changes the site's highest privilege level, so you need a rollback point and a clear record of what was changed.

Do not use the historical “admin2 / secret” SQL on Joomla 6

Joomla's administrator-recovery documentation still shows an older SQL example for creating an administrator, but the same current page explicitly warns that its direct-database password material is outdated for Joomla 5 password storage. That makes the legacy known-password SQL unsuitable as a Joomla 6.1.3 recovery recipe.

Regain temporary privileged access with the current recovery path

Use the version-appropriate recovery procedure documented by Joomla. The official recovery page describes a temporary $root_user setting in configuration.php that can elevate a known account for recovery. Follow the current instructions carefully and protect configuration.php while the emergency setting exists.

Create the replacement Super User inside Joomla

After temporary Administrator access is restored, open Users → Manage and select New. Enter a unique name, login name, email address, and strong password. In Assigned User Groups, assign Super Users only if the account genuinely requires unrestricted site administration. Save the account.

Test the new account before removing recovery access

Open a separate private browser session and sign in to /administrator with the new account. Confirm that it can perform the required Super User administration. Do not remove the only working recovery path until this test succeeds.

Remove the emergency elevation immediately

Once the new normal account is proven, remove the temporary $root_user recovery setting from configuration.php. Recheck the file and its access controls. Leaving an emergency elevation in place defeats the purpose of restoring normal account security.

Audit why the original access was lost

Review the existing Super Users, blocked states, group assignments, authentication and MFA settings, and relevant logs. If compromise is possible, rotate affected credentials and investigate the site rather than simply adding another privileged account.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket