CVE-2026-92227 CVE-2026-92222 CVE-2026-92231 CVE-2026-92232 CVE-2026-90913 CVE-2026-90915 CVE-2026-92226 CVE-2026-90907 CVE-2026-90917 CVE-2026-90918
Joomla CMS 5.4.9 and 6.1.4 fix MFA bypass, SSRF, XSS and access control flaws
Joomla CMS before 5.4.9 and 6.1.4 has several high-severity issues: MFA bypass, SSRF, XSS filter bypasses, and improper access checks including unauthorised account creation. Upgrade to Joomla CMS 5.4.9 or 6.1.4.
What happened
This Joomla security release fixes ten issues in Joomla CMS. The most consequential are CVE-2026-92227, where a remember-me cookie is issued prematurely and lets an attacker bypass multi-factor authentication, and CVE-2026-92222, where improperly validated URLs used for server-side requests create SSRF vectors that can reach internal services. CVE-2026-90907 allows unauthenticated creation of guest-level user accounts through the profile.save controller, even on sites where user registration is disabled.
Several other flaws involve improper access checks. CVE-2026-90913 and CVE-2026-92226 let unauthorised users perform mutation or edit actions on webservice endpoints or otherwise uneditable items; CVE-2026-90917 lets unauthorised users view content from inaccessible categories. CVE-2026-90915 allows arbitrary directory deletion through a path traversal in the cache purge action.
The release also addresses XSS filter bypasses in InputFilter (CVE-2026-92231 and CVE-2026-92232) and missing escaping in HTML mail templates (CVE-2026-90918). Some require an authenticated user with elevated privileges, but others, including MFA bypass, account creation, tagged-item access and mail-template XSS, do not. Joomla has not said that any of these flaws are being exploited.
Who is affected
Joomla CMS versions 1.5.0 through 5.4.8 and 6.0.0 through 6.1.3 are affected by this bundle. The MFA bypass, SSRF, ACL and directory-deletion flaws affect 4.0.0-5.4.8 and 6.0.0-6.1.3; the account-creation and InputFilter XSS issues go back to 1.5.0. Joomla Framework Filter package versions 1.0.0-3.0.6 and 4.0.0-4.1.0 are affected by the two InputFilter XSS bypasses. Joomla's advisory lists Joomla CMS 5.4.9 and 6.1.4 as fixed; it does not list a fixed version for the Framework Filter package.
What to do now
- Upgrade Joomla CMS to 5.4.9 if you are on any affected release from 1.5.0 through 5.4.8, or to 6.1.4 if you are on 6.0.0-6.1.3. Do this before other remediation.
- For Joomla Framework Filter package, no fixed version is listed in Joomla's advisory, so no upgrade instruction can be given here.
- Joomla's advisory does not list workarounds. If you cannot patch immediately, restrict network access to Joomla administrative and webservice endpoints, and monitor account creation and cache purge activity closely.
- After patching, verify that user accounts, webservice permissions and cache directories are as expected.
How to detect it
Joomla's advisory does not include indicators of compromise, but the descriptions point to specific places to look. Review user directories for accounts created while registration was disabled, particularly guest-level or unexpected accounts. Audit webservice logs for mutation or edit operations by users who should not have access, and content views from restricted categories. Look for unexpected deletion of directories related to cache storage. For CVE-2026-92227, review admin login records for sessions where a remember-me cookie was used without a completed MFA challenge.
Beyond the patch
Access-control and input-validation fixes like these are often deployed quickly, but the deeper exposure is the internet-facing Joomla surface itself: several of these issues assume an attacker can already reach the application or its webservice endpoints. Virtual CISO Services (vCISO) can help map and reduce that exposure, and Implementation & Assessment Services can verify the access-control and input-validation changes after you patch, and test for similar issues before the next release.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-92227, CVE-2026-92222, CVE-2026-90913, CVE-2026-90915, CVE-2026-92226, CVE-2026-90917, CVE-2026-90918 Joomla! CMS | 4.0.0-5.4.8 6.0.0-6.1.3 | 5.4.9 6.1.4 |
| CVE-2026-92231, CVE-2026-92232, CVE-2026-90907 Joomla! CMS | 1.5.0-5.4.8 6.0.0-6.1.3 | 5.4.9 6.1.4 |
| CVE-2026-92231, CVE-2026-92232 Joomla! Framework Filter package | 1.0.0-3.0.6 4.0.0-4.1.0 | No fixed version listed yet |
References
Vendor advisory
- Joomla! security announcement [20260914]: MFA Authentication Bypass through rememberme …
- Joomla! security announcement [20260909]: SSRF vectors in various core extensions
- Joomla! security announcement [20260915]: XSS filter bypass in InputFilter via HTML5 en…
- Joomla! security announcement [20260916]: XSS filter bypass in InputFilter via whitespa…
- Joomla! security announcement [20260903]: Improper ACL checks for access level webservi…
- Joomla! security announcement [20260905]: Arbitrary directory deletion via cache purge …
- Joomla! security announcement [20260913]: Improper ACL checks for varous webservice edi…
- Joomla! security announcement [20260902]: Unauthorized user account creation via profil…
Other
CVE
- CVE-2026-92227 — cve.org
- CVE-2026-92227 — NVD
- EUVD-2026-89074 — ENISA EUVD
- CVE-2026-92222 — cve.org
- CVE-2026-92222 — NVD
- EUVD-2026-89079 — ENISA EUVD
- CVE-2026-92231 — cve.org
- CVE-2026-92231 — NVD
- EUVD-2026-89082 — ENISA EUVD
- CVE-2026-92232 — cve.org
- CVE-2026-92232 — NVD
- EUVD-2026-89073 — ENISA EUVD
- CVE-2026-90913 — cve.org
- CVE-2026-90913 — NVD
- EUVD-2026-89115 — ENISA EUVD
- CVE-2026-90915 — cve.org
- CVE-2026-90915 — NVD
- EUVD-2026-89088 — ENISA EUVD
- CVE-2026-92226 — cve.org
- CVE-2026-92226 — NVD
- EUVD-2026-89087 — ENISA EUVD
- CVE-2026-90907 — cve.org
- CVE-2026-90907 — NVD
- EUVD-2026-89085 — ENISA EUVD
- CVE-2026-90917 — cve.org
- CVE-2026-90917 — NVD
- EUVD-2026-89076 — ENISA EUVD
- CVE-2026-90918 — cve.org
- CVE-2026-90918 — NVD
- EUVD-2026-89080 — ENISA EUVD