MFA Authentication Bypass Vulnerability in Joomla! Core
CVE-2026-92227
8.2HIGH
What is CVE-2026-92227?
A vulnerability in the Joomla! Core allows an attacker to bypass Multi-Factor Authentication (MFA) due to improper handling of 'rememberme' cookies. This flaw affects multiple versions of Joomla from 4.0.0 to 6.1.3, potentially compromising user accounts by allowing unauthorized access without additional verification.
Affected Version(s)
Joomla! CMS 4.0.0-5.4.8
Joomla! CMS 6.0.0-6.1.3