Security
Joomla fixes unauthorized account creation vulnerability
Administrators running Joomla! CMS 1.5.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4, respectively, to address an unauthorized user-account creation flaw.
The Joomla project has disclosed a vulnerability in the profile.save controller that can allow users who are not logged in to create guest-level accounts. This remains possible on installations where user registration has been disabled, creating a route around the site’s intended account-creation controls.
The advisory classifies the issue as Moderate severity, with Moderate impact and Moderate probability. Its exploit type is Authorization Bypass Through User-Controlled Key, and the vulnerability is tracked as CVE-2026-90907.
- Affected versions: Joomla! CMS
1.5.0-5.4.8and6.0.0-6.1.3 - Fixed versions:
5.4.9and6.1.4 - Fixed date: 2026-09-25
Site owners should apply the appropriate update for their branch, especially if registration is disabled as part of their security configuration. Developers and administrators should also review whether unexpected guest-level accounts were created before the update was installed.
Published by the Joomla Security Centre.