Unauthorized User Account Creation in Joomla! Core by Joomla
CVE-2026-90907

6.9MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-90907?

An access control vulnerability in the Joomla! Core allows unauthorized users to create guest-level user accounts through the profile.save controller. This flaw arises because the controller fails to verify the login state of the user, which could lead to potential abuse on sites lacking active user registration. The issue affects multiple Joomla versions (1.5.0-6.1.3), posing risks to site security and user management. Organizations using Joomla should update to recent secure versions to mitigate this vulnerability.

Affected Version(s)

Joomla! CMS 1.5.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adithyan P
.