Skip to content

CVE-2026-92227 CVE-2026-92222 CVE-2026-92231 CVE-2026-92232 CVE-2026-90913 CVE-2026-90915 CVE-2026-92226 CVE-2026-90907 CVE-2026-90917 CVE-2026-90918

Joomla CMS 5.4.9 and 6.1.4 fix MFA bypass, SSRF, XSS and access control flaws

High 8.9 Vendor: Joomla! Published

Joomla CMS before 5.4.9 and 6.1.4 has several high-severity issues: MFA bypass, SSRF, XSS filter bypasses, and improper access checks including unauthorised account creation. Upgrade to Joomla CMS 5.4.9 or 6.1.4.

What happened

This Joomla security release fixes ten issues in Joomla CMS. The most consequential are CVE-2026-92227, where a remember-me cookie is issued prematurely and lets an attacker bypass multi-factor authentication, and CVE-2026-92222, where improperly validated URLs used for server-side requests create SSRF vectors that can reach internal services. CVE-2026-90907 allows unauthenticated creation of guest-level user accounts through the profile.save controller, even on sites where user registration is disabled.

Several other flaws involve improper access checks. CVE-2026-90913 and CVE-2026-92226 let unauthorised users perform mutation or edit actions on webservice endpoints or otherwise uneditable items; CVE-2026-90917 lets unauthorised users view content from inaccessible categories. CVE-2026-90915 allows arbitrary directory deletion through a path traversal in the cache purge action.

The release also addresses XSS filter bypasses in InputFilter (CVE-2026-92231 and CVE-2026-92232) and missing escaping in HTML mail templates (CVE-2026-90918). Some require an authenticated user with elevated privileges, but others, including MFA bypass, account creation, tagged-item access and mail-template XSS, do not. Joomla has not said that any of these flaws are being exploited.

Who is affected

Joomla CMS versions 1.5.0 through 5.4.8 and 6.0.0 through 6.1.3 are affected by this bundle. The MFA bypass, SSRF, ACL and directory-deletion flaws affect 4.0.0-5.4.8 and 6.0.0-6.1.3; the account-creation and InputFilter XSS issues go back to 1.5.0. Joomla Framework Filter package versions 1.0.0-3.0.6 and 4.0.0-4.1.0 are affected by the two InputFilter XSS bypasses. Joomla's advisory lists Joomla CMS 5.4.9 and 6.1.4 as fixed; it does not list a fixed version for the Framework Filter package.

What to do now

  1. Upgrade Joomla CMS to 5.4.9 if you are on any affected release from 1.5.0 through 5.4.8, or to 6.1.4 if you are on 6.0.0-6.1.3. Do this before other remediation.
  2. For Joomla Framework Filter package, no fixed version is listed in Joomla's advisory, so no upgrade instruction can be given here.
  3. Joomla's advisory does not list workarounds. If you cannot patch immediately, restrict network access to Joomla administrative and webservice endpoints, and monitor account creation and cache purge activity closely.
  4. After patching, verify that user accounts, webservice permissions and cache directories are as expected.

How to detect it

Joomla's advisory does not include indicators of compromise, but the descriptions point to specific places to look. Review user directories for accounts created while registration was disabled, particularly guest-level or unexpected accounts. Audit webservice logs for mutation or edit operations by users who should not have access, and content views from restricted categories. Look for unexpected deletion of directories related to cache storage. For CVE-2026-92227, review admin login records for sessions where a remember-me cookie was used without a completed MFA challenge.

Beyond the patch

Access-control and input-validation fixes like these are often deployed quickly, but the deeper exposure is the internet-facing Joomla surface itself: several of these issues assume an attacker can already reach the application or its webservice endpoints. Virtual CISO Services (vCISO) can help map and reduce that exposure, and Implementation & Assessment Services can verify the access-control and input-validation changes after you patch, and test for similar issues before the next release.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-92227, CVE-2026-92222, CVE-2026-90913, CVE-2026-90915, CVE-2026-92226, CVE-2026-90917, CVE-2026-90918
Joomla! CMS
4.0.0-5.4.8
6.0.0-6.1.3
5.4.9
6.1.4
CVE-2026-92231, CVE-2026-92232, CVE-2026-90907
Joomla! CMS
1.5.0-5.4.8
6.0.0-6.1.3
5.4.9
6.1.4
CVE-2026-92231, CVE-2026-92232
Joomla! Framework Filter package
1.0.0-3.0.6
4.0.0-4.1.0
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.