Skip to content
Threat Feed
high advisory

Authorization Bypass in Joomla! CMS via CVE-2026-90907

An unauthenticated authorization bypass vulnerability in the Joomla! CMS 'com_users' component allows attackers to create accounts even when public registration is disabled.

CVE search metadata

CVE search record: CVE-2026-90907. EPSS: 0.25%. KEV: no. Product: Joomla! CMS (1.5.0 - 5.4.8), Joomla! CMS (6.0.0 - 6.1.3). Brief: Authorization Bypass in Joomla! CMS via CVE-2026-90907. Brief link: https://feed.craftedsignal.io/briefs/2026-10-joomla-cve-2026-90907/

CVE-2026-90907 is an authorization bypass vulnerability affecting the Joomla! CMS core, specifically within the com_users component's profile.save task. The vulnerability stems from improper session state management where an attacker can influence the user state by submitting an invalid request, followed by a valid registration request that skips necessary validation checks. This allows unauthenticated, remote attackers to create new user accounts regardless of the site's 'Allow User Registration' configuration.

The issue was disclosed in a security release on 2026-09-29 and affects Joomla! versions 1.5.0 through 5.4.8, as well as 6.0.0 through 6.1.3. Joomla! 3.x is also impacted but is End-of-Life and will not receive a patch. While the resulting accounts are low-privileged, this vulnerability enables attackers to reserve usernames, trigger registration-related plugins, and probe internal application logic. Defenders should prioritize patching and audit user databases for suspicious accounts created after 2026-09-29.

Attack Chain

  1. The attacker initiates a session with the target Joomla! instance by accessing the registration or profile endpoint.
  2. The attacker sends a POST request (W1) to the profile.save controller containing a non-compliant username and omitting the required privacyconsent field.
  3. The com_users controller processes the request, encounters a validation failure, and incorrectly persists the dirty user state in the session.
  4. The attacker sends a second POST request (W2) within the same session, this time providing a clean username and the required privacyconsent value.
  5. The ProfileModel::save() function incorrectly uses the session state to perform an unset() check, which is bypassed due to the state manipulation in step 3.
  6. The application performs an INSERT operation into the #__users table, successfully creating a new user account despite disabled registration.
  7. The application returns a 303 redirect indicating successful account creation (user_id > 0).

Impact

Successful exploitation allows unauthorized account creation, bypassing global configuration restrictions. While the accounts lack administrative rights, they can be used to reserve identifiers, trigger background registration hooks, or provide a foothold for further enumeration and probing of the Joomla! application logic. The vulnerability affects a broad range of versions, and given the availability of public exploit code, systems remaining unpatched are at immediate risk of account proliferation.

Recommendation

  • Upgrade all instances of Joomla! CMS to versions 5.4.9 or 6.1.4 immediately to remediate CVE-2026-90907.
  • Audit the Joomla! user database for unauthorized accounts created since 2026-09-29, particularly if public registration was intended to be disabled.
  • Implement web application firewall (WAF) rules to detect and block sequential POST requests to com_users endpoints originating from a single session that exhibit the pattern of a failed registration followed by a successful one.
  • Migrate legacy Joomla! 3.x installations as they are End-of-Life and will not receive security updates for this vulnerability.

Immediate actions

Upgrade Joomla! CMS instances to 5.4.9 or 6.1.4.

IT Operations 24h

Threat Hunt

Search user database for accounts created after 2026-09-29.

T1190 high high confidence hunt now

Data: Joomla user registration logs/database

Mitigations

Upgrade to latest patched version.

immediate IT Operations

CVE-2026-90907

Detection coverage 1

Detects CVE-2026-90907 Exploitation Attempt - Account Creation

high

Detects repeated POST requests to profile.save in the same session, where a failed attempt precedes a successful one indicating potential exploitation.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →