2FA Bypass Vulnerability in Joomla Core Authentication
CVE-2026-48897
8.2HIGH
What is CVE-2026-48897?
A security flaw in Joomla's core authentication mechanism allows an attacker to bypass two-factor authentication (2FA) checks due to insufficient state validation. This vulnerability can potentially enable unauthorized access, compromising user accounts and sensitive data, making it crucial for administrators to apply relevant patches and updates promptly.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.5
Joomla! CMS 6.0.0-6.1.0