Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla tagged-item ACL flaw exposes restricted content

Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4. The issue is an Incorrect Access Control vulnerability with CVE identifier CVE-2026-90917 and a severity of Moderate.

The Joomla project says the flaw affects output handling for tagged items. An improper permission check can allow unauthorized users to view content items belonging to categories they cannot access. The issue is therefore relevant to sites that use category restrictions alongside tagging.

The advisory records the impact as Low and the probability as Moderate. Although the issue is described as a viewing problem rather than a way to modify content, exposed items may contain information intended only for users with access to their category. Site owners should treat category permissions and tagged-content output as part of the same review.

  • Upgrade Joomla! CMS installations to the appropriate fixed release.
  • Check custom templates, overrides and extensions that render tagged items after updating.
  • Review access settings for categories containing information that should not be publicly visible.

Amin İsayev reported the issue on 2026-07-28, and the Joomla project lists 2026-09-25 as the fixed date. The advisory identifies the affected subproject as CMS and the project as Joomla!.

Published by the Joomla Security Centre.