Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
https://developer.joomla.org/security-centre/661-20161003-core-account-modifications.html