Joomla · Joomla! · CVE-2026-90907
**Name of the Vulnerable Software and Affected Versions**
Joomla! Core versions 1.5.0 through 5.4.8
Joomla! Core versions 6.0.0 through 6.1.3
**Description**
The `profile.save` controller fails to verify the login state of a user. This allows the unauthorized creation of guest-level user accounts on websites where user registration is disabled.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.