CVE-2026-90907 is a missing authentication check in the Joomla! Core profile.save controller affecting versions 1.5.0 through 5.4.8 and 6.0.0 through 6.1.3. The controller fails to verify the user's login state, allowing unauthenticated remote attackers to create guest-level user accounts even when user registration is disabled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This five-file Python repository contains a standalone operational exploit and behavioral checker for CVE-2026-90907, an authorization-bypass issue in Joomla! CMS com_users profile.save handling. The primary 42 KB entry point, joomla_cve_2026_90907.py, uses requests and a persistent HTTP session to retrieve a token, conduct a two-step profile-save sequence, and optionally create a real low-privilege account. The first request intentionally fails validation while retaining a non-compliant username in guest-session state; the second request reuses that state with consent enabled to attempt insertion of the supplied account. Default CHECK mode avoids consent and is intended not to create an account; EXPLOIT mode is enabled only by supplying -U. The script supports proxying, configurable TLS verification, timeout and User-Agent options, verbose request/response logging, generated passwords, result exit codes, and evidence output. Evidence directories contain token, version, seed, exploit, and login-verification artifacts plus summary.json. Other repository files are README documentation, a requests dependency declaration, MIT license, and gitignore rules for generated evidence.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthorized account-creation vulnerability in Joomla!'s profile.save controller affects versions 1.5.0–5.4.8 and 6.0.0–6.1.3. Missing login-state checks allow guest-level account creation even when user registration is disabled. Nessus identifies exposure from the application's self-reported version rather than testing exploitation.
An authorization flaw in the Joomla! Core profile.save controller that fails to verify a user's login state, allowing unauthenticated creation of guest-level accounts even where user registration is disabled.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.