Authorization bypass through user-controlled key in Joomla! - CVE-2026-90907
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to create guest-level user accounts.
The vulnerability exists due to authorization bypass through a user-controlled key in the profile.save controller when processing profile.save requests. A remote attacker can send a request to the profile.save controller to create guest-level user accounts.
User registration does not need to be active.