Path traversal in Joomla! - CVE-2026-90915
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to delete arbitrary directories.
The vulnerability exists due to improper validation of cache group names in the cache layer file storage when processing cache purge actions. A remote attacker can submit a cache group name containing path traversal sequences to delete arbitrary directories.