Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes unauthorized account creation vulnerability

Administrators running Joomla! CMS 1.5.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4, respectively, to address an unauthorized user-account creation flaw.

The Joomla project has disclosed a vulnerability in the profile.save controller that can allow users who are not logged in to create guest-level accounts. This remains possible on installations where user registration has been disabled, creating a route around the site’s intended account-creation controls.

The advisory classifies the issue as Moderate severity, with Moderate impact and Moderate probability. Its exploit type is Authorization Bypass Through User-Controlled Key, and the vulnerability is tracked as CVE-2026-90907.

  • Affected versions: Joomla! CMS 1.5.0-5.4.8 and 6.0.0-6.1.3
  • Fixed versions: 5.4.9 and 6.1.4
  • Fixed date: 2026-09-25

Site owners should apply the appropriate update for their branch, especially if registration is disabled as part of their security configuration. Developers and administrators should also review whether unexpected guest-level accounts were created before the update was installed.

Published by the Joomla Security Centre.