{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/joomla-cms-1.5.0---5.4.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:joomla:joomla_cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-90907"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Joomla! CMS (1.5.0 - 5.4.8)","Joomla! CMS (6.0.0 - 6.1.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Joomla"],"content_html":"\u003cp\u003eCVE-2026-90907 is an authorization bypass vulnerability affecting the Joomla! CMS core, specifically within the \u003ccode\u003ecom_users\u003c/code\u003e component's \u003ccode\u003eprofile.save\u003c/code\u003e task. The vulnerability stems from improper session state management where an attacker can influence the user state by submitting an invalid request, followed by a valid registration request that skips necessary validation checks. This allows unauthenticated, remote attackers to create new user accounts regardless of the site's 'Allow User Registration' configuration.\u003c/p\u003e\n\u003cp\u003eThe issue was disclosed in a security release on 2026-09-29 and affects Joomla! versions 1.5.0 through 5.4.8, as well as 6.0.0 through 6.1.3. Joomla! 3.x is also impacted but is End-of-Life and will not receive a patch. While the resulting accounts are low-privileged, this vulnerability enables attackers to reserve usernames, trigger registration-related plugins, and probe internal application logic. Defenders should prioritize patching and audit user databases for suspicious accounts created after 2026-09-29.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker initiates a session with the target Joomla! instance by accessing the registration or profile endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a POST request (W1) to the \u003ccode\u003eprofile.save\u003c/code\u003e controller containing a non-compliant username and omitting the required \u003ccode\u003eprivacyconsent\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecom_users\u003c/code\u003e controller processes the request, encounters a validation failure, and incorrectly persists the dirty user state in the session.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a second POST request (W2) within the same session, this time providing a clean username and the required \u003ccode\u003eprivacyconsent\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eProfileModel::save()\u003c/code\u003e function incorrectly uses the session state to perform an \u003ccode\u003eunset()\u003c/code\u003e check, which is bypassed due to the state manipulation in step 3.\u003c/li\u003e\n\u003cli\u003eThe application performs an \u003ccode\u003eINSERT\u003c/code\u003e operation into the \u003ccode\u003e#__users\u003c/code\u003e table, successfully creating a new user account despite disabled registration.\u003c/li\u003e\n\u003cli\u003eThe application returns a \u003ccode\u003e303\u003c/code\u003e redirect indicating successful account creation (user_id \u0026gt; 0).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized account creation, bypassing global configuration restrictions. While the accounts lack administrative rights, they can be used to reserve identifiers, trigger background registration hooks, or provide a foothold for further enumeration and probing of the Joomla! application logic. The vulnerability affects a broad range of versions, and given the availability of public exploit code, systems remaining unpatched are at immediate risk of account proliferation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Joomla! CMS to versions 5.4.9 or 6.1.4 immediately to remediate CVE-2026-90907.\u003c/li\u003e\n\u003cli\u003eAudit the Joomla! user database for unauthorized accounts created since 2026-09-29, particularly if public registration was intended to be disabled.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to detect and block sequential POST requests to \u003ccode\u003ecom_users\u003c/code\u003e endpoints originating from a single session that exhibit the pattern of a failed registration followed by a successful one.\u003c/li\u003e\n\u003cli\u003eMigrate legacy Joomla! 3.x installations as they are End-of-Life and will not receive security updates for this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T17:23:26Z","date_published":"2026-10-01T17:23:26Z","id":"https://feed.craftedsignal.io/briefs/2026-10-joomla-cve-2026-90907/","summary":"An unauthenticated authorization bypass vulnerability in the Joomla! CMS 'com_users' component allows attackers to create accounts even when public registration is disabled.","title":"Authorization Bypass in Joomla! CMS via CVE-2026-90907","url":"https://feed.craftedsignal.io/briefs/2026-10-joomla-cve-2026-90907/"}],"language":"en","title":"CraftedSignal Threat Feed - Joomla! CMS (1.5.0 - 5.4.8)","version":"https://jsonfeed.org/version/1.1"}