Junglewise Threat Intelligence

CVE-2026-48897: Joomla! CMS multi-factor authentication bypass

CVE-2026-48897 · Severity: info · CVSS 8.2 · Published 2026-05-26

Technologies: Joomla CMS. Vendors: Joomla.

Executive brief

A vulnerability in the Joomla! content management system allows attackers to bypass multi-factor authentication (MFA) protections. Joomla! is widely used to build and manage websites; an exploit of this nature could allow an unauthorized user to gain access to accounts even if they have two-factor authentication enabled. This could lead to unauthorized site modifications, data theft, or full administrative takeover of the website.

Technical details

An authentication bypass vulnerability exists in Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0 due to improper authentication (CWE-287). The root cause is incorrectly reset session states during the multi-factor authentication (MFA) process. A remote, unauthenticated attacker can exploit this flaw to bypass 2FA requirements and gain unauthorized access to user accounts. The attack requires the 'Attack Requirements' (AT) of 'Present' in CVSS 4.0, suggesting specific conditions must be met during the session state transition. The issue is resolved in Joomla! versions 5.4.6 and 6.1.1.

Affected products

  • Joomla! CMS 4.0.0 - 5.4.5, 6.0.0 - 6.1.0

Timeline

  • 2026-04-01: disclosed: Reported to Joomla! Project
  • 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
  • 2026-05-26: advisory

References