Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes ACL checks in content history comparison

Administrators running affected Joomla CMS releases should upgrade to the available maintenance versions to prevent unauthorized viewing of restricted content.

The Joomla project has addressed an access-control flaw in the Joomla! CMS content history comparison view. The issue could allow users without the necessary permissions to see content that should be inaccessible to them.

The affected releases are 4.0.0-5.4.8 and 6.0.0-6.1.3. Administrators should update to 5.4.9 or 6.1.4, respectively.

  • CVE: CVE-2026-90916
  • Exploit type: Incorrect Access Control
  • Severity: Low
  • Impact: Low
  • Probability: Low

The advisory concerns the core content history comparison functionality. Although the project rates the issue as Low severity, sites should apply the relevant update because the flaw affects authorization checks and may expose content across permission boundaries.

Published by the Joomla Security Centre.