CVE-2026-48896
Two-Factor Authentication Bypass in Joomla
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: Joomla! Project
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| joomla | joomla_cms | From 4.0.0 (inc) to 5.4.5 (inc) |
| joomla | joomla_cms | From 6.0.0 (inc) to 6.1.0 (inc) |
| joomla | joomla_cms | 5.4.6 |
| joomla | joomla_cms | 6.1.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-48896 is a security vulnerability in Joomla! CMS that allows an attacker to bypass Multi-Factor Authentication (MFA) due to insufficient state checks.
This means that the system does not properly verify certain states during the authentication process, enabling unauthorized users to circumvent the 2FA security layer.
The vulnerability affects Joomla! CMS versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0.
How can this vulnerability impact me? :
This vulnerability can have a high impact as it allows attackers to bypass the Multi-Factor Authentication mechanism, potentially gaining unauthorized access to user accounts.
By bypassing 2FA, attackers can compromise sensitive information, perform unauthorized actions, and escalate privileges within the Joomla! CMS environment.
Users of affected Joomla! versions are advised to upgrade to versions 5.4.6 or 6.1.1 to mitigate this risk.
What immediate steps should I take to mitigate this vulnerability?
To mitigate the vulnerability CVE-2026-48896 in Joomla! CMS, users should upgrade affected Joomla! versions to the fixed releases.
- Upgrade Joomla! CMS versions 4.0.0 through 5.4.5 to version 5.4.6 or later.
- Upgrade Joomla! CMS versions 6.0.0 through 6.1.0 to version 6.1.1 or later.
For further assistance, contact the Joomla! Security Strike Team (JSST) at the Joomla! Security Centre.