CVE-2026-90907: Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3
Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.
Affected Software
Event History
Frequently Asked Questions
Which Joomla installations are exposed?
Joomla versions 1.5.0 through 5.4.8 and 6.0.0 through 6.1.3 are affected. Sites are exposed even when user registration is not active.
What does an attacker need to exploit this issue?
An attacker does not need to be logged in. The affected profile.save controller fails to verify the user's login state, allowing creation of a guest-level account.
How can administrators identify possible exploitation?
Review user accounts for unexpected guest-level accounts, particularly on sites where user registration was disabled. The supplied information does not provide request signatures or other indicators beyond unauthorized account creation.