PT-2026-102691 · Joomla · Joomla!

·

CVE-2026-90915

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Joomla! Core versions 4.0.0 through 5.4.8 Joomla! Core versions 6.0.0 through 6.1.3
Description Improper validation of the cache group name allows path traversal within the file storage of the caching layer. This flaw enables the arbitrary deletion of directories via the cache purge action.
Recommendations Update Joomla! Core versions 4.0.0 through 5.4.8 to a version newer than 5.4.8. Update Joomla! Core versions 6.0.0 through 6.1.3 to a version newer than 6.1.3.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90915

Affected Products

Joomla!