Arbitrary Directory Deletion in Joomla! Core by Joomla
CVE-2026-90915

7HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-90915?

An improper validation of the cache group name in Joomla! Core allows for path traversal vulnerabilities, enabling potential attackers to delete arbitrary directories via the cache purge action. This affects versions 4.0.0 through 4.0.8 and 6.0.0 through 6.1.3, which could compromise the integrity of the installation.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aria Akhavan
Calif.io in collaboration with Anthropic
.