How to Reset a Joomla Administrator Password

If you can still sign in with another authorized administrator account, reset the affected administrator's password from Joomla itself. This is safer than editing password hashes in the database and lets Joomla store the new password using the password mechanism supported by the installed version.

Reset the password from Users

  1. Sign in to Joomla Administrator with an account permitted to manage users.
  2. Open Users → Manage.
  3. Select the affected administrator's name.
  4. Enter the new value in Password and enter it again in Confirm Password.
  5. Select Save or Save & Close.

Current Joomla Help5.x documents Password and Confirm Password as account fields and identifies the Users list as the place to find and edit users.

Use a unique password and preserve the user's role

A password reset should not require changing the user's Assigned User Groups. Leave group membership alone unless the access problem is actually an ACL problem. Use a unique password appropriate to your organization's security policy and do not send it through an insecure channel.

Consider Require Password Reset

If an administrator is setting a temporary password for another person, the user-edit screen can require the user to reset the password on the next login. Use that option when it fits your account-recovery policy, then have the user choose a private password after authenticating.

If the user can reset the password themselves

Joomla's frontend Login module includes a forgotten-password link, and a Password Reset menu item can expose the reset form directly. That flow sends a recovery message to the email address associated with the account. Confirm the account email is correct and Joomla mail is working before relying on it.

If no administrator can log in

Do not paste an old public MD5 or salted-MD5 hash into a Joomla 6 database. Joomla's current administrator-recovery documentation explicitly warns that its historical direct-database password examples are outdated for Joomla 5-era password storage. Use a current recovery procedure for the installed version, such as the documented temporary $root_user recovery mechanism when appropriate, then reset the password normally inside Joomla.

Verify the account after the reset

Log out and test the affected account in a clean browser session. Confirm that the new password works, the account is Enabled, multi-factor authentication still behaves as expected, and the administrator has only the intended permissions. If the reset was triggered by suspected compromise, review other privileged accounts and relevant logs instead of treating the password change as the entire incident response.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket