CVE-2026-90917: Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3
Published Sep 29, 2026
·Updated
Joomla! Core - [20260907] - Core - Improper ACL checks in outputs for tagged items in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - An improper access check allows unauthorized users to view content items from inaccessible categories.
Affected Software
1 affected component
Joomla Joomla Core>=4.0.0<=5.4.8, >=6.0.0<=6.1.3
Event History
Sep 29, 2026
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Joomla Core versions are affected?
The affected versions are Joomla 4.0.0 through 5.4.8 and Joomla 6.0.0 through 6.1.3.
2
What access could an unauthorized user gain?
An unauthorized user may be able to view content items that belong to categories they are not permitted to access, through outputs for tagged items.