How to Reset a Joomla Password Directly in the Database
For a current Joomla 6 site, directly replacing the #__users.password value with a legacy hash from an old tutorial is not a reliable password-reset method. Joomla's own recovery documentation warns that its historical direct-database password examples are outdated for Joomla 5-era password storage. Use a current supported recovery path instead of inventing a hash.
Do not use the old MD5 recipes on Joomla 6
Older Joomla documentation and third-party tutorials commonly tell administrators to place an MD5 or salted-MD5 value in the users table. The current official administrator-recovery page now warns that those procedures do not work with modern Joomla 5 password storage. The QuantaCade Joomla 6.1.3 baseline is newer still, so this article does not provide a legacy hash as though it were valid.
Back up the database before any recovery work
If you are locked out and have database access, take a current database backup before changing any user record. Confirm the site's actual table prefix from configuration.php; #__users is Joomla's prefix-neutral notation, not a literal table name to type into every database.
Prefer Joomla's documented recovery mechanism
The current Joomla administrator-recovery documentation describes a temporary public $root_user='username'; setting in configuration.php for emergency recovery using a known account. Follow the official recovery instructions for the installed Joomla version, regain Administrator access, and then set a new password through Users → Manage so Joomla creates the stored password representation itself.
If you must work at database level, do not guess the hash algorithm
Database-level recovery is security-sensitive and version-dependent. Do not copy a hash from another site, use a public default password, change the user ID, or blindly add a user-to-group mapping. Those actions can create a known privileged credential or damage account relationships. If a current Joomla release provides a version-specific database recovery procedure, follow that exact procedure and verify it against the installed release before executing it.
Reset normally after access is restored
Once you can enter Joomla Administrator, open the account in Users → Manage, set a unique password in Password and Confirm Password, and save. Remove any temporary emergency elevation from configuration.php immediately after normal privileged access is working.
Verify and audit
Log out and sign back in with the repaired account. Confirm the account is Enabled and has the intended groups only. If you were locked out unexpectedly, review privileged users, recent configuration changes, authentication/MFA configuration, and logs for evidence of compromise.
Need More Help with Joomla?
Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.
Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.
QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.