Joomla let anyone create an admin account, even with registration disabled
"I turned off registration, so nobody can create an account." Sounds reasonable, and for years it was true. Until, in 2016, a flaw in Joomla turned that assumption on its head.
What happened
A bug in the registration mechanism (CVE-2016-8869 and CVE-2016-8870) allowed creating user accounts even when registration was disabled and instantly assigning the new account administrator privileges. The result: a stranger joined the site as a full owner, and the panel looked normal.
The flaw affected versions 3.4.4-3.6.3. The fix came with 3.6.4, and it was a race against time, because the first real attacks were noted within tens of hours of the patch being published.
Why it is sneaky
There were no "symptoms". The site worked, looked fine, and in the background had a new administrator waiting for the right moment. It is the classic silent-takeover scenario, the most dangerous, because it is invisible.
What to do
- Regularly review the user list and their privileges. An unknown administrator account is an alarm.
- Update the Joomla core immediately after a critical patch is released.
- Enable two-factor authentication for administrative accounts.
A silent administrator is one of those problems that only come to light during a review. We run such reviews routinely, see how care works.
Sources: NVD, CVE-2016-8869, NVD, CVE-2016-8870.