Authorization Bypass in Joomla! CMS via CVE-2026-90907
An unauthenticated authorization bypass vulnerability in the Joomla! CMS 'com_users' component allows attackers to create accounts even when public registration is disabled.
CVE search metadata
CVE search record: CVE-2026-90907. EPSS: 0.25%. KEV: no. Product: Joomla! CMS (1.5.0 - 5.4.8), Joomla! CMS (6.0.0 - 6.1.3). Brief: Authorization Bypass in Joomla! CMS via CVE-2026-90907. Brief link: https://feed.craftedsignal.io/briefs/2026-10-joomla-cve-2026-90907/
CVE-2026-90907 is an authorization bypass vulnerability affecting the Joomla! CMS core, specifically within the com_users component's profile.save task. The vulnerability stems from improper session state management where an attacker can influence the user state by submitting an invalid request, followed by a valid registration request that skips necessary validation checks. This allows unauthenticated, remote attackers to create new user accounts regardless of the site's 'Allow User Registration' configuration.
The issue was disclosed in a security release on 2026-09-29 and affects Joomla! versions 1.5.0 through 5.4.8, as well as 6.0.0 through 6.1.3. Joomla! 3.x is also impacted but is End-of-Life and will not receive a patch. While the resulting accounts are low-privileged, this vulnerability enables attackers to reserve usernames, trigger registration-related plugins, and probe internal application logic. Defenders should prioritize patching and audit user databases for suspicious accounts created after 2026-09-29.
Attack Chain
- The attacker initiates a session with the target Joomla! instance by accessing the registration or profile endpoint.
- The attacker sends a POST request (W1) to the
profile.savecontroller containing a non-compliant username and omitting the requiredprivacyconsentfield. - The
com_userscontroller processes the request, encounters a validation failure, and incorrectly persists the dirty user state in the session. - The attacker sends a second POST request (W2) within the same session, this time providing a clean username and the required
privacyconsentvalue. - The
ProfileModel::save()function incorrectly uses the session state to perform anunset()check, which is bypassed due to the state manipulation in step 3. - The application performs an
INSERToperation into the#__userstable, successfully creating a new user account despite disabled registration. - The application returns a
303redirect indicating successful account creation (user_id > 0).
Impact
Successful exploitation allows unauthorized account creation, bypassing global configuration restrictions. While the accounts lack administrative rights, they can be used to reserve identifiers, trigger background registration hooks, or provide a foothold for further enumeration and probing of the Joomla! application logic. The vulnerability affects a broad range of versions, and given the availability of public exploit code, systems remaining unpatched are at immediate risk of account proliferation.
Recommendation
- Upgrade all instances of Joomla! CMS to versions 5.4.9 or 6.1.4 immediately to remediate CVE-2026-90907.
- Audit the Joomla! user database for unauthorized accounts created since 2026-09-29, particularly if public registration was intended to be disabled.
- Implement web application firewall (WAF) rules to detect and block sequential POST requests to
com_usersendpoints originating from a single session that exhibit the pattern of a failed registration followed by a successful one. - Migrate legacy Joomla! 3.x installations as they are End-of-Life and will not receive security updates for this vulnerability.
Immediate actions
Upgrade Joomla! CMS instances to 5.4.9 or 6.1.4.
Threat Hunt
Search user database for accounts created after 2026-09-29.
Data: Joomla user registration logs/database
Mitigations
Upgrade to latest patched version.
CVE-2026-90907
Detection coverage 1
Detects CVE-2026-90907 Exploitation Attempt - Account Creation
highDetects repeated POST requests to profile.save in the same session, where a failed attempt precedes a successful one indicating potential exploitation.
Detection queries are available on the platform. Get full rules →