2FA Bypass Vulnerability in Joomla Core Authentication
CVE-2026-48897

8.2HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-48897?

A security flaw in Joomla's core authentication mechanism allows an attacker to bypass two-factor authentication (2FA) checks due to insufficient state validation. This vulnerability can potentially enable unauthorized access, compromising user accounts and sensitive data, making it crucial for administrators to apply relevant patches and updates promptly.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.5

Joomla! CMS 6.0.0-6.1.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Morris Baumgarten-Egemole
.