Joomla Fixes 16 Security Issues as 5.4.9 Breaks API PATCH Requests

"SECURITY." "Security Fixes Meet an Upgrade Complication." "Joomla patches 16 core issues while a Web Services regression adds another post update check." The Joomla logo appears above a connected system diagram where a broken orange connection interrupts a sequence of servers and components.

Joomla released versions 6.1.4 and 5.4.9 on September 29, 2026, with fixes for 16 core security issues. The project's release announcement directs administrators on supported Joomla 6 and Joomla 5 branches to apply the updates.

Version 5.4.9 also introduces a regression affecting Web Services API PATCH requests. Joomla's known-issues documentation says requests to update resources such as users or banners can fail with a fatal error because a required Doctrine\Inflector\InflectorFactory import was omitted while security fixes were being ported to the 5.x branch. Joomla has documented a workaround and says a permanent fix is planned for version 5.4.10.

Joomla's Security Centre classifies two of the 16 vulnerabilities as High severity, 13 as Moderate and one as Low. The project has not reported active exploitation. Individual affected-version ranges vary, so the release should not be read as meaning that every vulnerability applies to every older Joomla installation.

CVE-2026-90915 and CVE-2026-92222 receive Joomla's High severity classification. CVE-2026-90915 concerns path traversal in the file-cache implementation that can allow arbitrary directory deletion under affected conditions. CVE-2026-92222 covers server-side request forgery caused by insufficient validation of URLs used for server-side requests. Joomla classifies both as High impact with Low probability.

Another advisory, CVE-2026-92227, addresses an MFA authentication bypass involving remember-me cookies issued too early in the authentication process. Joomla rates the issue as Moderate severity and Moderate probability but High impact, and lists versions 4.0.0 through 5.4.8 and 6.0.0 through 6.1.3 as affected. Other fixes address missing access-control checks around API endpoints, unauthorised Web Services edit operations, workflow stage changes, tagged content exposure, account creation through profile.save and content-history access.

Several cross-site scripting vulnerabilities are also included. The affected areas include HTMLHelper::link, media layouts, HTML mail templates, toolbar and module-list rendering, along with two InputFilter bypasses involving HTML5 entity decoding and whitespace handling in data URIs.

Published information for CVE-2026-92222 contains a version-range discrepancy. Joomla's advisory metadata gives an affected range beginning with Joomla 3.0.0, while its affected-installs description begins with Joomla 4.0.0. Administrators assessing older installations should therefore consult the current advisory rather than relying on a single generalised lower version boundary.

Sites using Joomla 5.4 Web Services integrations need an additional regression check after applying the security update. Joomla's workaround adds the missing import responsible for the PATCH failure, while 5.4.10 is expected to provide the permanent correction. At the time of writing, Joomla's official downloads list 5.4.9 as the latest Joomla 5 release.

Joomla 5.4 remains under bug-fix support through October 13, 2026, and security support through October 12, 2027. Joomla 5 sites are therefore not required to move immediately to Joomla 6, but installations using API-driven workflows should test those integrations after updating rather than treating successful installation of the security release as the end of the upgrade process.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Related Organizations

Upcoming Events

Latest Opportunities