Executive brief
A vulnerability in the Joomla! content management system allows attackers to bypass multi-factor authentication (MFA) protections. Joomla! is widely used to build and manage websites; an exploit of this flaw could allow an attacker to gain unauthorized access to user accounts even if they have 2FA enabled. This could lead to unauthorized site modifications, data theft, or full administrative takeover of the website.
Technical details
An authentication bypass vulnerability exists in Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The flaw is rooted in improper authentication (CWE-287) due to insufficient state checks during the multi-factor authentication (MFA) process. A remote, unauthenticated attacker can exploit this logic flaw to circumvent 2FA requirements and gain access to protected accounts. The vulnerability has been addressed in Joomla! versions 5.4.6 and 6.1.1. The CVSS 4.0 score of 8.2 reflects a high impact on integrity with a network attack vector, though it requires specific conditions (Attack Terminology: Provider) to be met.
Affected products
- Joomla! CMS 4.0.0 - 5.4.5, 6.0.0 - 6.1.0
Timeline
- 2026-04-01: other: Reported to vendor
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: disclosed