{"api_version":"1","generated_at":"2026-07-23T04:31:31+00:00","cve":"CVE-2016-8870","urls":{"html":"https://cve.report/CVE-2016-8870","api":"https://cve.report/api/cve/CVE-2016-8870.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8870","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8870"},"summary":{"title":"CVE-2016-8870","description":"The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.","state":"PUBLISHED","assigner":"mitre","published_at":"2016-11-04 21:59:08","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.1","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securitytracker.com/id/1037108","name":"http://www.securitytracker.com/id/1037108","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Joomla! Input Validation Flaw Lets Remote Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r","name":"https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Joomla (< 3.6.4) Account Creation/Elevated Privileges write-up and exploit – Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1037107","name":"http://www.securitytracker.com/id/1037107","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Joomla! Access Control Flaw Lets Remote Users Register on the Target System When Registration is Disabled - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93876","name":"http://www.securityfocus.com/bid/93876","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Joomla! Core CVE-2016-8870 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privesc","name":"http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privesc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"CVE-2016-8870 Joomla Account Creation and Privilege Escalation | Rapid7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/40637/","name":"https://www.exploit-db.com/exploits/40637/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html","name":"https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Details on the Privilege Escalation Vulnerability in Joomla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html","name":"https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"[20161001] - Core - Account Creation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcf","name":"https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Prepare 3.6.4 Stable Release · joomla/joomla-cms@bae1d43 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/@showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r","name":"MISC:https://medium.com/@showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r","refsource":"MITRE","tags":[],"title":"Joomla (< 3.6.4) Account Creation/Elevated Privileges write-up and exploit – Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8870","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8870","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8870","vulnerable":"1","versionEndIncluding":"3.6.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"joomla","cpe5":"joomla\\!","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2016","cve_id":"8870","cve":"CVE-2016-8870","epss":"0.915130000","percentile":"0.996790000","score_date":"2026-05-10","updated_at":"2026-05-11 00:14:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:35:01.133Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"93876","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/93876"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privesc"},{"name":"40637","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/40637/"},{"name":"1037108","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1037108"},{"name":"1037107","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1037107"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-10-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"93876","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/93876"},{"tags":["x_refsource_MISC"],"url":"https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html"},{"tags":["x_refsource_MISC"],"url":"http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privesc"},{"name":"40637","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/40637/"},{"name":"1037108","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1037108"},{"name":"1037107","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1037107"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcf"},{"tags":["x_refsource_MISC"],"url":"https://medium.com/%40showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2016-8870","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"93876","refsource":"BID","url":"http://www.securityfocus.com/bid/93876"},{"name":"https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html","refsource":"MISC","url":"https://blog.sucuri.net/2016/10/details-on-the-privilege-escalation-vulnerability-in-joomla.html"},{"name":"https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html","refsource":"CONFIRM","url":"https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html"},{"name":"http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privesc","refsource":"MISC","url":"http://www.rapid7.com/db/modules/auxiliary/admin/http/joomla_registration_privesc"},{"name":"40637","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/40637/"},{"name":"1037108","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037108"},{"name":"1037107","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037107"},{"name":"https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcf","refsource":"CONFIRM","url":"https://github.com/joomla/joomla-cms/commit/bae1d43938c878480cfd73671e4945211538fdcf"},{"name":"https://medium.com/@showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r","refsource":"MISC","url":"https://medium.com/@showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.rq4qh1v4r"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2016-8870","datePublished":"2016-11-04T21:00:00.000Z","dateReserved":"2016-10-21T00:00:00.000Z","dateUpdated":"2024-08-06T02:35:01.133Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-11-04 21:59:08","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:joomla:joomla\\!:*:*:*:*:*:*:*:*","versionEndIncluding":"3.6.3","matchCriteriaId":"59292C00-859C-4F23-B92F-D525DDA76582"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8870","Ordinal":"1","Title":"CVE-2016-8870","CVE":"CVE-2016-8870","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8870","Ordinal":"1","NoteData":"The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.","Type":"Description","Title":"CVE-2016-8870"},{"CveYear":"2016","CveId":"8870","Ordinal":"2","NoteData":"2016-11-04","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8870","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}