Security
Joomla cache purge flaw could delete arbitrary directories
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4, respectively. The High-severity issue, tracked as CVE-2026-90915, is a Path Traversal vulnerability that can result in arbitrary directory…
The Joomla project’s advisory describes insufficient checking of cache group names in the caching layer’s file storage. A specially crafted name could navigate outside the expected cache location, allowing directories to be removed from the filesystem.
The affected product is Joomla! CMS. The project rates the impact as High and the probability as Low. Administrators should select the corrective release for their major version branch and review their update process if they manage multiple Joomla installations.
4.0.0-5.4.8is affected; upgrade to5.4.9.6.0.0-6.1.3is affected; upgrade to6.1.4.
The issue was reported on 2026-08-13 and fixed on 2026-09-25. The advisory credits Aria Akhavan of Calif.io, in collaboration with Anthropic, for reporting it. The Joomla Security Strike Team can be contacted through the Joomla Security Centre.
Published by the Joomla Security Centre.