CVE-2016-9081
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
Date published : 2017-01-23
http://www.securityfocus.com/bid/93969
https://developer.joomla.org/security-centre/661-20161003-core-account-modifications.html