Vulnerability record · CVE-2016-8869 · published 4 November 2016
CVE-2016-8869: Joomla Users component registration privilege escalation
Joomla · Joomla\!
The register method in the UsersModelRegistration class in Joomla's Users component mishandles unfiltered data during account registration, allowing privilege escalation. Joomla versions before 3.6.4 are affected, and the flaw is remotely reachable without authentication.
Description
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, very high EPSS, and public exploit code make this a high-risk, easily exploitable flaw.
What it is
The register method in the UsersModelRegistration class in Joomla's Users component mishandles unfiltered data during account registration, allowing privilege escalation. Joomla versions before 3.6.4 are affected, and the flaw is remotely reachable without authentication.
Impact
An attacker can register an account that gains elevated privileges, potentially taking administrative control of the site.
Attack surface
Reached over the network through the site's user registration endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.97244, 99.9th percentile) and public exploit references exist, including Exploit-DB 40637 and a Rapid7 Metasploit module.
What to do
- Upgrade Joomla to 3.6.4 or later, which contains the fix in commit bae1d43938c878480cfd73671e4945211538fdcf.
- If immediate upgrade is not possible, disable or restrict public user registration until patched.
- Review existing user accounts for unexpected elevated roles created through registration.
- Apply the vendor security advisory guidance from Joomla's security centre.
- Monitor registration endpoints for anomalous account creation patterns.
Detection
- Audit user accounts for newly registered users with elevated privileges or unexpected group assignments.
- Review web server and Joomla logs for registration requests containing unusual or malformed parameters.
- Alert on registration activity from IPs or user agents associated with known exploit tooling.
- Correlate account creation events with subsequent administrative actions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-8869 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-8869), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.