Unauthorized User Account Creation in Joomla! Core by Joomla
CVE-2026-90907
6.9MEDIUM
What is CVE-2026-90907?
An access control vulnerability in the Joomla! Core allows unauthorized users to create guest-level user accounts through the profile.save controller. This flaw arises because the controller fails to verify the login state of the user, which could lead to potential abuse on sites lacking active user registration. The issue affects multiple Joomla versions (1.5.0-6.1.3), posing risks to site security and user management. Organizations using Joomla should update to recent secure versions to mitigate this vulnerability.
Affected Version(s)
Joomla! CMS 1.5.0-5.4.8
Joomla! CMS 6.0.0-6.1.3